Jump to content


Photo

Please Help


  • This topic is locked This topic is locked
25 replies to this topic

#1 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 25 July 2004 - 08:21 AM

I think i have a trojan called 'Trojan.Ecure'. I have been trying for a week to manually remove the trojan but i just dont know how. I have read numerous web pages about this trojan and how to defeat it but i just cant seem to do it. Could somebody please help me?


my hijack this log is:

Logfile of HijackThis v1.97.7
Scan saved at 14:25:43, on 24/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\crmn32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\sm56hlpr.exe
C:\WINDOWS\system32\msmd32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\System32\gxyd.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe
C:\Program Files\MSN Messenger\msnmsgr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe
O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe
O4 - HKLM\..\RunOnce: [msiv32.exe] C:\WINDOWS\system32\msiv32.exe
O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe
O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe
O4 - HKLM\..\RunOnce: [crcf.exe] C:\WINDOWS\system32\crcf.exe
O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
O4 - HKLM\..\RunOnce: [syscn32.exe] C:\WINDOWS\syscn32.exe
O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe
O4 - HKLM\..\RunOnce: [sdkup32.exe] C:\WINDOWS\system32\sdkup32.exe
O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe
O4 - HKLM\..\RunOnce: [javaof.exe] C:\WINDOWS\system32\javaof.exe
O4 - HKLM\..\RunOnce: [atlyc.exe] C:\WINDOWS\system32\atlyc.exe
O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe
O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe
O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe
O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe
O4 - HKLM\..\RunOnce: [addws.exe] C:\WINDOWS\system32\addws.exe
O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe
O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe
O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe
O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe
O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe
O4 - HKLM\..\RunOnce: [sysbd.exe] C:\WINDOWS\sysbd.exe
O4 - HKLM\..\RunOnce: [d3yi.exe] C:\WINDOWS\system32\d3yi.exe
O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe
O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe
O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe
O4 - HKLM\..\RunOnce: [sysrj.exe] C:\WINDOWS\system32\sysrj.exe
O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe
O4 - HKLM\..\RunOnce: [ntit32.exe] C:\WINDOWS\system32\ntit32.exe
O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe
O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe
O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe
O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe
O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe
O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe
O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe
O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe
O4 - HKLM\..\RunOnce: [addky.exe] C:\WINDOWS\system32\addky.exe
O4 - HKLM\..\RunOnce: [netuv32.exe] C:\WINDOWS\netuv32.exe
O4 - HKLM\..\RunOnce: [iecw.exe] C:\WINDOWS\iecw.exe
O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe
O4 - HKLM\..\RunOnce: [atlhk.exe] C:\WINDOWS\system32\atlhk.exe
O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe
O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\system32\d3qy.exe
O4 - HKLM\..\RunOnce: [netdn32.exe] C:\WINDOWS\netdn32.exe
O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe
O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe
O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe
O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe
O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe
O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe
O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe
O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe
O4 - HKLM\..\RunOnce: [ieqc32.exe] C:\WINDOWS\system32\ieqc32.exe
O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe
O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe
O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe
O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\system32\sysxo.exe
O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe
O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe
O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe
O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe
O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe
O4 - HKLM\..\RunOnce: [atlzr32.exe] C:\WINDOWS\atlzr32.exe
O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe
O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe
O4 - HKLM\..\RunOnce: [crqg32.exe] C:\WINDOWS\crqg32.exe
O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe
O4 - HKLM\..\RunOnce: [netkw32.exe] C:\WINDOWS\netkw32.exe
O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe
O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe
O4 - HKLM\..\RunOnce: [sdkmi.exe] C:\WINDOWS\system32\sdkmi.exe
O4 - HKLM\..\RunOnce: [sysmc.exe] C:\WINDOWS\system32\sysmc.exe
O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe
O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe
O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe
O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe
O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe
O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe
O4 - HKLM\..\RunOnce: [ipzq32.exe] C:\WINDOWS\ipzq32.exe
O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\system32\d3km32.exe
O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe
O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe
O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe
O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe
O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe
O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\system32\atlfd32.exe
O4 - HKLM\..\RunOnce: [ntun.exe] C:\WINDOWS\ntun.exe
O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe
O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe
O4 - HKLM\..\RunOnce: [sdkbv32.exe] C:\WINDOWS\system32\sdkbv32.exe
O4 - HKLM\..\RunOnce: [ipfl32.exe] C:\WINDOWS\ipfl32.exe
O4 - HKLM\..\RunOnce: [javauo32.exe] C:\WINDOWS\system32\javauo32.exe
O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe
O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe
O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe
O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe
O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe
O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe
O4 - HKLM\..\RunOnce: [apist.exe] C:\WINDOWS\system32\apist.exe
O4 - HKLM\..\RunOnce: [msoj.exe] C:\WINDOWS\msoj.exe
O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe
O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe
O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe
O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe
O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe
O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe
O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe
O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe
O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe
O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe
O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe
O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe
O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe
O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe
O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe
O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe
O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe
O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe
O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe
O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe
O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe
O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe
O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe
O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe
O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe
O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe
O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe
O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe
O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe
O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe
O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe
O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe
O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe
O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe
O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe
O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe
O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe
O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe
O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe
O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe
O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe
O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Money Viewer (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wsluoiro.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.1...m::/on-line.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.1....chm::/load.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamesp...nch/alaunch.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38188.580787037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#2 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 25 July 2004 - 09:00 AM

First disconnect your computer from the Internet.
Now do a Ctrl-Alt-Delete in order to bring up Task Manager and, on the Processes tab, end task on these processes:

msmd32.exe
gxyd.exe

Now find the following files, and delete them:

C:\WINDOWS\system32\msmd32.exe
C:\WINDOWS\System32\gxyd.exe

NOTE: To avoid the risk of the files not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show.

Now run Hijack This again, and check and have it fix the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe

O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe
O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe
O4 - HKLM\..\RunOnce: [msiv32.exe] C:\WINDOWS\system32\msiv32.exe
O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe
O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe
O4 - HKLM\..\RunOnce: [crcf.exe] C:\WINDOWS\system32\crcf.exe
O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
O4 - HKLM\..\RunOnce: [syscn32.exe] C:\WINDOWS\syscn32.exe
O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe
O4 - HKLM\..\RunOnce: [sdkup32.exe] C:\WINDOWS\system32\sdkup32.exe
O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe
O4 - HKLM\..\RunOnce: [javaof.exe] C:\WINDOWS\system32\javaof.exe
O4 - HKLM\..\RunOnce: [atlyc.exe] C:\WINDOWS\system32\atlyc.exe
O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe
O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe
O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe
O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe
O4 - HKLM\..\RunOnce: [addws.exe] C:\WINDOWS\system32\addws.exe
O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe
O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe
O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe
O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe
O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe
O4 - HKLM\..\RunOnce: [sysbd.exe] C:\WINDOWS\sysbd.exe
O4 - HKLM\..\RunOnce: [d3yi.exe] C:\WINDOWS\system32\d3yi.exe
O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe
O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe
O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe
O4 - HKLM\..\RunOnce: [sysrj.exe] C:\WINDOWS\system32\sysrj.exe
O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe
O4 - HKLM\..\RunOnce: [ntit32.exe] C:\WINDOWS\system32\ntit32.exe
O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe
O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe
O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe
O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe
O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe
O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe
O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe
O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe
O4 - HKLM\..\RunOnce: [addky.exe] C:\WINDOWS\system32\addky.exe
O4 - HKLM\..\RunOnce: [netuv32.exe] C:\WINDOWS\netuv32.exe
O4 - HKLM\..\RunOnce: [iecw.exe] C:\WINDOWS\iecw.exe
O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe
O4 - HKLM\..\RunOnce: [atlhk.exe] C:\WINDOWS\system32\atlhk.exe
O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe
O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\system32\d3qy.exe
O4 - HKLM\..\RunOnce: [netdn32.exe] C:\WINDOWS\netdn32.exe
O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe
O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe
O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe
O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe
O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe
O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe
O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe
O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe
O4 - HKLM\..\RunOnce: [ieqc32.exe] C:\WINDOWS\system32\ieqc32.exe
O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe
O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe
O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe
O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\system32\sysxo.exe
O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe
O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe
O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe
O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe
O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe
O4 - HKLM\..\RunOnce: [atlzr32.exe] C:\WINDOWS\atlzr32.exe
O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe
O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe
O4 - HKLM\..\RunOnce: [crqg32.exe] C:\WINDOWS\crqg32.exe
O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe
O4 - HKLM\..\RunOnce: [netkw32.exe] C:\WINDOWS\netkw32.exe
O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe
O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe
O4 - HKLM\..\RunOnce: [sdkmi.exe] C:\WINDOWS\system32\sdkmi.exe
O4 - HKLM\..\RunOnce: [sysmc.exe] C:\WINDOWS\system32\sysmc.exe
O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe
O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe
O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe
O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe
O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe
O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe
O4 - HKLM\..\RunOnce: [ipzq32.exe] C:\WINDOWS\ipzq32.exe
O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\system32\d3km32.exe
O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe
O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe
O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe
O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe
O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe
O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\system32\atlfd32.exe
O4 - HKLM\..\RunOnce: [ntun.exe] C:\WINDOWS\ntun.exe
O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe
O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe
O4 - HKLM\..\RunOnce: [sdkbv32.exe] C:\WINDOWS\system32\sdkbv32.exe
O4 - HKLM\..\RunOnce: [ipfl32.exe] C:\WINDOWS\ipfl32.exe
O4 - HKLM\..\RunOnce: [javauo32.exe] C:\WINDOWS\system32\javauo32.exe
O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe
O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe
O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe
O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe
O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe
O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe
O4 - HKLM\..\RunOnce: [apist.exe] C:\WINDOWS\system32\apist.exe
O4 - HKLM\..\RunOnce: [msoj.exe] C:\WINDOWS\msoj.exe
O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe
O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe
O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe
O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe
O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe
O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe
O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe
O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe
O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe
O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe
O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe
O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe
O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe
O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe
O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe
O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe
O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe
O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe
O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe
O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe
O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe
O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe
O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe
O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe
O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe
O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe
O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe
O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe
O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe
O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe
O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe
O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe
O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe
O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe
O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe
O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe
O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe
O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe
O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe
O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe
O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe
O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe

O15 - Trusted Zone: *.blazefind.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.my-internet.info
O15 - Trusted Zone: *.searchbarcash.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotch.com

O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wsluoiro.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.1...m::/on-line.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.1....chm::/load.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab


Next, download About:Buster from here

http://www.downloads...AboutBuster.zip

Now start your computer in Safe Mode.

Unzip About:Buster to your desktop. Double click it and hit Ok, then Start, then Ok to start the scan. The scan should take a few seconds. Once it is done save the report.

Reboot normally, and run an online virus scan at http://housecall.antivirus.com/

When done, post the About: Buster report and a new Hijack this log here.

#3 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 25 July 2004 - 12:53 PM

Thankyou for your instructions. i shall start now and inform you as soon as possible. :-)

#4 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 25 July 2004 - 01:23 PM

hi. I searched and deleted the 'gxyd.exe' but i couldn't find 'msmd32.exe'. I then ran Hijack This and began scanning through your list and checking boxes when i noticed this difference:

You had told me to check and fix the following;
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049

However in my Hijack This scan my two files were different, mine looked like this;

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html


At this point i stopped and i would like to know if you feel this difference is significant before continuing.


To help you, i have updated my hijack this log.

Logfile of HijackThis v1.97.7
Scan saved at 19:18:19, on 25/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\crmn32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\sm56hlpr.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\msmd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\secure.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe
O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe
O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe
O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe
O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe
O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe
O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe
O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe
O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe
O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe
O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe
O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe
O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe
O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe
O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe
O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe
O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe
O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe
O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe
O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe
O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe
O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe
O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe
O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe
O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe
O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe
O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe
O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe
O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe
O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe
O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe
O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe
O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe
O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe
O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe
O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe
O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe
O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe
O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe
O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe
O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe
O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe
O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe
O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe
O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe
O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe
O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe
O4 - HKLM\..\RunOnce: [atlfy.exe] C:\WINDOWS\atlfy.exe
O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe
O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe
O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe
O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe
O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe
O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe
O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe
O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe
O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe
O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe
O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe
O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe
O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe
O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe
O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe
O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe
O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe
O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe
O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe
O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe
O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe
O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe
O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe
O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe
O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe
O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe
O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe
O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe
O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe
O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe
O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe
O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe
O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe
O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe
O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe
O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe
O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe
O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe
O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe
O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe
O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe
O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe
O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe
O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe
O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe
O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe
O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe
O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe
O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe
O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe
O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe
O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe
O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe
O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe
O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe
O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe
O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe
O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe
O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\d3qy.exe
O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe
O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe
O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Money Viewer (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\wsluoiro.exe
O16 - DPF: {10003000-1000-0000-1000-000000000000} - ms-its:mhtml:file://C:\foo.mht!http://195.225.177.1...m::/on-line.exe
O16 - DPF: {11111111-1111-1111-1111-111111111157} - ms-its:mhtml:file://c:\nosuch.mht!http://213.159.117.1....chm::/load.exe
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamesp...nch/alaunch.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38188.580787037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#5 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 25 July 2004 - 01:26 PM

Did you run About-Buster at all? It doesnt look as if you did...

Would you please do this first:

Copy the contents of the 'QUOTE' box to Notepad, and save as GetServices.vbs (make sure you save as type: 'all files' )

Doubleclick GetServices.vbs (a script by Mosaic1), and it will produce a list of all active services on your computer; please post that list in your reply.

set objIdDictionary = CreateObject("Scripting.Dictionary")
strComputer = "."
Set objWMIService = GetObject("winmgmts:" _
    & "{impersonationLevel=impersonate}!\\" & strComputer & "\root\cimv2")
Set colServices = objWMIService.ExecQuery _
    ("Select * from Win32_Service Where State <> 'Stopped'")
For Each objService in colServices
    If objIdDictionary.Exists(objService.ProcessID) Then
    Else
        objIdDictionary.Add objService.ProcessID, objService.ProcessID
    End If
Next
colProcessIDs = objIdDictionary.Items
For i = 0 to objIdDictionary.Count - 1
    Set colServices = objWMIService.ExecQuery _
        ("Select * from Win32_Service Where ProcessID = '" & _
            colProcessIDs(i) & "'")
 
    For Each objService in colServices
        msg = msg & vbcrlf &  " " & Ucase(objService.DisplayName) & ":" & " " &  objService.Name & vbcrlf & objService.PathName &  vbcrlf

    Next
Next
Dim fso, Services,Wshshell
Set Wshshell = Wscript.CreateObject("Wscript.Shell")
Set fso = Wscript.CreateObject("Scripting.FileSystemObject")
Set Services = fso.CreateTextFile("Active.txt",true)
Services.Write "These are the Current Active Services:"
Services.WriteLine
Services.Write msg
Services.Close
Wshshell.Run "Active.txt"



If you have script blocking installed, you will get a warning when you try to run the script. Please allow it to run. It is only collecting information so we can help you.

#6 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 25 July 2004 - 03:04 PM

sorry about the problems but unfortunatly i have never heard of a program called 'About Buster'. I copied the quote into notepad and followed your instructions but when i double clicked it, the following error message appeared:

Script:  C:\WINDOWS\GetServices.vbs
Line:  32
Char:  1
Error:  The System Cannot Find The File Specified

Code:  80070002
Source:  (Null)



I had recieved some other advice but the moderator closed the topic so i couldnt reply. The advice from somebody else is shown below and im just wondering what you make of it because it is a very different approach.


You have a couple of different infections here. So let´s do it step by step.

Hello please download About:Buster and unzip it to your desktop. Don´t run it yet.

How to use Ad-Aware to remove Spyware <= Please check this link for instructions on how to download, install and then use adaware. Don´t use it yet.
1 You already have Adaware installed. Make sure it's up to date. Just open Adaware and click on *Check for Updates Now* and then *Connect*. It will find a new reference-file. Click *ok* and let it download and install the updates by clicking on *Finish* .This will return you to the main screen. You should now see Reference File # : 01R333 18.07.2004 or higher listed.

2 Print out these instructions so you have them handy as most of the steps need to be done in safe mode and you may not be able to go online.

3. Next, go to Start->Run and type "Services.msc" (without quotes) then hit Ok
Scroll down and find the service called "Network Security Service". When you find it, double-click on it. In the next window that opens, click the Stop button, then click on properties and under the General Tab, change the Startup Type to Disabled. Now hit Apply and then Ok and close any open windows. This service is installed by the malware. If this service is not listed go ahead with the next step.

4. Reboot to Safe Mode
How to start the computer in
Safe mode


5. Make sure your PC is configured to show hidden files

Open Windows Explorer & Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked.
Also uncheck "Hide protected operating system files" and untick "hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

6.CLOSE ALL WINDOWS AND BROWSERS Scan with Hijack This and put checks next to all the following, then click "Fix Checked"

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll
O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe
O4 - HKCU\..\Run: [Wocb] C:\Documents and Settings\Ashley\Application Data\raau.exe
O4 - HKCU\..\Run: [Xqavolax] C:\WINDOWS\System32\gxyd.exe
O4 - HKLM\..\RunOnce: [msiv32.exe] C:\WINDOWS\system32\msiv32.exe
O4 - HKLM\..\RunOnce: [ipil.exe] C:\WINDOWS\ipil.exe
O4 - HKLM\..\RunOnce: [addxb.exe] C:\WINDOWS\system32\addxb.exe
O4 - HKLM\..\RunOnce: [crcf.exe] C:\WINDOWS\system32\crcf.exe
O4 - HKLM\..\RunOnce: [ntoc.exe] C:\WINDOWS\ntoc.exe
O4 - HKLM\..\RunOnce: [syscn32.exe] C:\WINDOWS\syscn32.exe
O4 - HKLM\..\RunOnce: [msuk.exe] C:\WINDOWS\system32\msuk.exe
O4 - HKLM\..\RunOnce: [sdkup32.exe] C:\WINDOWS\system32\sdkup32.exe
O4 - HKLM\..\RunOnce: [winbo32.exe] C:\WINDOWS\system32\winbo32.exe
O4 - HKLM\..\RunOnce: [javaof.exe] C:\WINDOWS\system32\javaof.exe
O4 - HKLM\..\RunOnce: [atlyc.exe] C:\WINDOWS\system32\atlyc.exe
O4 - HKLM\..\RunOnce: [msrm32.exe] C:\WINDOWS\msrm32.exe
O4 - HKLM\..\RunOnce: [sysfh.exe] C:\WINDOWS\sysfh.exe
O4 - HKLM\..\RunOnce: [netnb.exe] C:\WINDOWS\system32\netnb.exe
O4 - HKLM\..\RunOnce: [atlfn.exe] C:\WINDOWS\system32\atlfn.exe
O4 - HKLM\..\RunOnce: [addws.exe] C:\WINDOWS\system32\addws.exe
O4 - HKLM\..\RunOnce: [crtt.exe] C:\WINDOWS\system32\crtt.exe
O4 - HKLM\..\RunOnce: [msbf32.exe] C:\WINDOWS\msbf32.exe
O4 - HKLM\..\RunOnce: [ntmo32.exe] C:\WINDOWS\ntmo32.exe
O4 - HKLM\..\RunOnce: [ipgu32.exe] C:\WINDOWS\system32\ipgu32.exe
O4 - HKLM\..\RunOnce: [msrq32.exe] C:\WINDOWS\msrq32.exe
O4 - HKLM\..\RunOnce: [sysbd.exe] C:\WINDOWS\sysbd.exe
O4 - HKLM\..\RunOnce: [d3yi.exe] C:\WINDOWS\system32\d3yi.exe
O4 - HKLM\..\RunOnce: [addfu.exe] C:\WINDOWS\addfu.exe
O4 - HKLM\..\RunOnce: [winpk.exe] C:\WINDOWS\winpk.exe
O4 - HKLM\..\RunOnce: [sysvu.exe] C:\WINDOWS\sysvu.exe
O4 - HKLM\..\RunOnce: [sysrj.exe] C:\WINDOWS\system32\sysrj.exe
O4 - HKLM\..\RunOnce: [mfccf.exe] C:\WINDOWS\system32\mfccf.exe
O4 - HKLM\..\RunOnce: [ntit32.exe] C:\WINDOWS\system32\ntit32.exe
O4 - HKLM\..\RunOnce: [msxn32.exe] C:\WINDOWS\system32\msxn32.exe
O4 - HKLM\..\RunOnce: [mfcmc.exe] C:\WINDOWS\mfcmc.exe
O4 - HKLM\..\RunOnce: [ipmn32.exe] C:\WINDOWS\system32\ipmn32.exe
O4 - HKLM\..\RunOnce: [ntig32.exe] C:\WINDOWS\ntig32.exe
O4 - HKLM\..\RunOnce: [sysfp32.exe] C:\WINDOWS\system32\sysfp32.exe
O4 - HKLM\..\RunOnce: [d3vw32.exe] C:\WINDOWS\d3vw32.exe
O4 - HKLM\..\RunOnce: [apiae32.exe] C:\WINDOWS\system32\apiae32.exe
O4 - HKLM\..\RunOnce: [ntzl.exe] C:\WINDOWS\system32\ntzl.exe
O4 - HKLM\..\RunOnce: [addky.exe] C:\WINDOWS\system32\addky.exe
O4 - HKLM\..\RunOnce: [netuv32.exe] C:\WINDOWS\netuv32.exe
O4 - HKLM\..\RunOnce: [iecw.exe] C:\WINDOWS\iecw.exe
O4 - HKLM\..\RunOnce: [apigk32.exe] C:\WINDOWS\system32\apigk32.exe
O4 - HKLM\..\RunOnce: [atlhk.exe] C:\WINDOWS\system32\atlhk.exe
O4 - HKLM\..\RunOnce: [appat.exe] C:\WINDOWS\appat.exe
O4 - HKLM\..\RunOnce: [d3qy.exe] C:\WINDOWS\system32\d3qy.exe
O4 - HKLM\..\RunOnce: [netdn32.exe] C:\WINDOWS\netdn32.exe
O4 - HKLM\..\RunOnce: [netgc.exe] C:\WINDOWS\system32\netgc.exe
O4 - HKLM\..\RunOnce: [crfm32.exe] C:\WINDOWS\crfm32.exe
O4 - HKLM\..\RunOnce: [javatb.exe] C:\WINDOWS\javatb.exe
O4 - HKLM\..\RunOnce: [sysar.exe] C:\WINDOWS\system32\sysar.exe
O4 - HKLM\..\RunOnce: [apinn32.exe] C:\WINDOWS\system32\apinn32.exe
O4 - HKLM\..\RunOnce: [crjo.exe] C:\WINDOWS\crjo.exe
O4 - HKLM\..\RunOnce: [winig32.exe] C:\WINDOWS\system32\winig32.exe
O4 - HKLM\..\RunOnce: [ieoz.exe] C:\WINDOWS\system32\ieoz.exe
O4 - HKLM\..\RunOnce: [ieqc32.exe] C:\WINDOWS\system32\ieqc32.exe
O4 - HKLM\..\RunOnce: [ipyg32.exe] C:\WINDOWS\ipyg32.exe
O4 - HKLM\..\RunOnce: [mskg32.exe] C:\WINDOWS\system32\mskg32.exe
O4 - HKLM\..\RunOnce: [javawb.exe] C:\WINDOWS\system32\javawb.exe
O4 - HKLM\..\RunOnce: [sysxo.exe] C:\WINDOWS\system32\sysxo.exe
O4 - HKLM\..\RunOnce: [sdkkd.exe] C:\WINDOWS\sdkkd.exe
O4 - HKLM\..\RunOnce: [appoy32.exe] C:\WINDOWS\system32\appoy32.exe
O4 - HKLM\..\RunOnce: [javace.exe] C:\WINDOWS\javace.exe
O4 - HKLM\..\RunOnce: [msgx32.exe] C:\WINDOWS\msgx32.exe
O4 - HKLM\..\RunOnce: [atlgr32.exe] C:\WINDOWS\atlgr32.exe
O4 - HKLM\..\RunOnce: [atlzr32.exe] C:\WINDOWS\atlzr32.exe
O4 - HKLM\..\RunOnce: [winpy32.exe] C:\WINDOWS\winpy32.exe
O4 - HKLM\..\RunOnce: [javaqi.exe] C:\WINDOWS\system32\javaqi.exe
O4 - HKLM\..\RunOnce: [crqg32.exe] C:\WINDOWS\crqg32.exe
O4 - HKLM\..\RunOnce: [javazk32.exe] C:\WINDOWS\javazk32.exe
O4 - HKLM\..\RunOnce: [netkw32.exe] C:\WINDOWS\netkw32.exe
O4 - HKLM\..\RunOnce: [iehp.exe] C:\WINDOWS\system32\iehp.exe
O4 - HKLM\..\RunOnce: [apiob32.exe] C:\WINDOWS\system32\apiob32.exe
O4 - HKLM\..\RunOnce: [sdkmi.exe] C:\WINDOWS\system32\sdkmi.exe
O4 - HKLM\..\RunOnce: [sysmc.exe] C:\WINDOWS\system32\sysmc.exe
O4 - HKLM\..\RunOnce: [ipse32.exe] C:\WINDOWS\system32\ipse32.exe
O4 - HKLM\..\RunOnce: [netgt32.exe] C:\WINDOWS\netgt32.exe
O4 - HKLM\..\RunOnce: [d3qh.exe] C:\WINDOWS\system32\d3qh.exe
O4 - HKLM\..\RunOnce: [netpp32.exe] C:\WINDOWS\system32\netpp32.exe
O4 - HKLM\..\RunOnce: [crzn.exe] C:\WINDOWS\crzn.exe
O4 - HKLM\..\RunOnce: [appid32.exe] C:\WINDOWS\appid32.exe
O4 - HKLM\..\RunOnce: [ipzq32.exe] C:\WINDOWS\ipzq32.exe
O4 - HKLM\..\RunOnce: [d3km32.exe] C:\WINDOWS\system32\d3km32.exe
O4 - HKLM\..\RunOnce: [d3ob.exe] C:\WINDOWS\d3ob.exe
O4 - HKLM\..\RunOnce: [ieyj32.exe] C:\WINDOWS\ieyj32.exe
O4 - HKLM\..\RunOnce: [apidb.exe] C:\WINDOWS\apidb.exe
O4 - HKLM\..\RunOnce: [crxd32.exe] C:\WINDOWS\crxd32.exe
O4 - HKLM\..\RunOnce: [sysnq.exe] C:\WINDOWS\sysnq.exe
O4 - HKLM\..\RunOnce: [atlfd32.exe] C:\WINDOWS\system32\atlfd32.exe
O4 - HKLM\..\RunOnce: [ntun.exe] C:\WINDOWS\ntun.exe
O4 - HKLM\..\RunOnce: [crgk32.exe] C:\WINDOWS\system32\crgk32.exe
O4 - HKLM\..\RunOnce: [apivk.exe] C:\WINDOWS\apivk.exe
O4 - HKLM\..\RunOnce: [sdkbv32.exe] C:\WINDOWS\system32\sdkbv32.exe
O4 - HKLM\..\RunOnce: [ipfl32.exe] C:\WINDOWS\ipfl32.exe
O4 - HKLM\..\RunOnce: [javauo32.exe] C:\WINDOWS\system32\javauo32.exe
O4 - HKLM\..\RunOnce: [netmq.exe] C:\WINDOWS\system32\netmq.exe
O4 - HKLM\..\RunOnce: [apiuy32.exe] C:\WINDOWS\system32\apiuy32.exe
O4 - HKLM\..\RunOnce: [sysdt32.exe] C:\WINDOWS\sysdt32.exe
O4 - HKLM\..\RunOnce: [nthr.exe] C:\WINDOWS\system32\nthr.exe
O4 - HKLM\..\RunOnce: [sdkal.exe] C:\WINDOWS\system32\sdkal.exe
O4 - HKLM\..\RunOnce: [d3do32.exe] C:\WINDOWS\system32\d3do32.exe
O4 - HKLM\..\RunOnce: [apist.exe] C:\WINDOWS\system32\apist.exe
O4 - HKLM\..\RunOnce: [msoj.exe] C:\WINDOWS\msoj.exe
O4 - HKLM\..\RunOnce: [crmn32.exe] C:\WINDOWS\system32\crmn32.exe
O4 - HKLM\..\RunOnce: [sdkth.exe] C:\WINDOWS\system32\sdkth.exe
O4 - HKLM\..\RunOnce: [netiq.exe] C:\WINDOWS\system32\netiq.exe
O4 - HKLM\..\RunOnce: [sdkgd.exe] C:\WINDOWS\system32\sdkgd.exe
O4 - HKLM\..\RunOnce: [apiiz32.exe] C:\WINDOWS\system32\apiiz32.exe
O4 - HKLM\..\RunOnce: [crzy32.exe] C:\WINDOWS\system32\crzy32.exe
O4 - HKLM\..\RunOnce: [ntiu.exe] C:\WINDOWS\system32\ntiu.exe
O4 - HKLM\..\RunOnce: [d3xp.exe] C:\WINDOWS\system32\d3xp.exe
O4 - HKLM\..\RunOnce: [appvi.exe] C:\WINDOWS\appvi.exe
O4 - HKLM\..\RunOnce: [addrp32.exe] C:\WINDOWS\addrp32.exe
O4 - HKLM\..\RunOnce: [ntaz32.exe] C:\WINDOWS\system32\ntaz32.exe
O4 - HKLM\..\RunOnce: [mfcls32.exe] C:\WINDOWS\system32\mfcls32.exe
O4 - HKLM\..\RunOnce: [apife32.exe] C:\WINDOWS\system32\apife32.exe
O4 - HKLM\..\RunOnce: [apihj32.exe] C:\WINDOWS\apihj32.exe
O4 - HKLM\..\RunOnce: [craw.exe] C:\WINDOWS\system32\craw.exe
O4 - HKLM\..\RunOnce: [mfcdw32.exe] C:\WINDOWS\system32\mfcdw32.exe
O4 - HKLM\..\RunOnce: [d3xg.exe] C:\WINDOWS\system32\d3xg.exe
O4 - HKLM\..\RunOnce: [apiei.exe] C:\WINDOWS\system32\apiei.exe
O4 - HKLM\..\RunOnce: [ipgx32.exe] C:\WINDOWS\system32\ipgx32.exe
O4 - HKLM\..\RunOnce: [sysbg.exe] C:\WINDOWS\sysbg.exe
O4 - HKLM\..\RunOnce: [iesc32.exe] C:\WINDOWS\system32\iesc32.exe
O4 - HKLM\..\RunOnce: [sysnq32.exe] C:\WINDOWS\sysnq32.exe
O4 - HKLM\..\RunOnce: [iehf.exe] C:\WINDOWS\system32\iehf.exe
O4 - HKLM\..\RunOnce: [sdkkj32.exe] C:\WINDOWS\sdkkj32.exe
O4 - HKLM\..\RunOnce: [cryo.exe] C:\WINDOWS\cryo.exe
O4 - HKLM\..\RunOnce: [ipvy32.exe] C:\WINDOWS\system32\ipvy32.exe
O4 - HKLM\..\RunOnce: [crsj.exe] C:\WINDOWS\system32\crsj.exe
O4 - HKLM\..\RunOnce: [sdkzj.exe] C:\WINDOWS\sdkzj.exe
O4 - HKLM\..\RunOnce: [apimk32.exe] C:\WINDOWS\system32\apimk32.exe
O4 - HKLM\..\RunOnce: [sysnt.exe] C:\WINDOWS\sysnt.exe
O4 - HKLM\..\RunOnce: [atlql.exe] C:\WINDOWS\atlql.exe
O4 - HKLM\..\RunOnce: [d3bz.exe] C:\WINDOWS\d3bz.exe
O4 - HKLM\..\RunOnce: [crua32.exe] C:\WINDOWS\system32\crua32.exe
O4 - HKLM\..\RunOnce: [sysud.exe] C:\WINDOWS\system32\sysud.exe
O4 - HKLM\..\RunOnce: [apicp.exe] C:\WINDOWS\system32\apicp.exe
O4 - HKLM\..\RunOnce: [adddz.exe] C:\WINDOWS\system32\adddz.exe

O4 - HKLM\..\RunOnce: [addrn.exe] C:\WINDOWS\addrn.exe
O4 - HKLM\..\RunOnce: [mfcxi32.exe] C:\WINDOWS\system32\mfcxi32.exe
O4 - HKLM\..\RunOnce: [nethq.exe] C:\WINDOWS\nethq.exe
O4 - HKLM\..\RunOnce: [crbx32.exe] C:\WINDOWS\crbx32.exe
O4 - HKLM\..\RunOnce: [ntms.exe] C:\WINDOWS\ntms.exe
O4 - HKLM\..\RunOnce: [d3up.exe] C:\WINDOWS\d3up.exe




7. Delete the following files if present.

C:\WINDOWS\sysdt32.exe
C:\WINDOWS\msoj.exe
C:\WINDOWS\ipfl32.exe
C:\WINDOWS\apivk.exe
C:\WINDOWS\ntun.exe
C:\WINDOWS\appvi.exe
C:\WINDOWS\addrp32.exe
C:\WINDOWS\apihj32.exe
C:\WINDOWS\sysnq32.exe
C:\WINDOWS\sdkkj32.exe
C:\WINDOWS\nethq.exe
C:\WINDOWS\cryo.exe
C:\WINDOWS\crbx32.exe
C:\WINDOWS\ntms.exe
C:\WINDOWS\d3up.exe
C:\WINDOWS\addrn.exe
C:\WINDOWS\sysnt.exe
C:\WINDOWS\atlql.exe
C:\WINDOWS\d3bz.exe
C:\WINDOWS\sdkzj.exe
C:\WINDOWS\sysbg.exe
C:\WINDOWS\msbf32.exe
C:\WINDOWS\ntmo32.exe
C:\WINDOWS\msrq32.exe
C:\WINDOWS\sysbd.exe
C:\WINDOWS\msrm32.exe
C:\WINDOWS\sysfh.exe
C:\WINDOWS\syscn32.exe
C:\WINDOWS\mfcmc.exe
C:\WINDOWS\ntig32.exe
C:\WINDOWS\d3vw32.exe
C:\WINDOWS\netuv32.exe
C:\WINDOWS\iecw.exe
C:\WINDOWS\addfu.exe
C:\WINDOWS\winpk.exe
C:\WINDOWS\sysvu.exe
C:\WINDOWS\ipil.exe
C:\WINDOWS\ntoc.exe
C:\WINDOWS\sdkkd.exe
C:\WINDOWS\ipyg32.exe
C:\WINDOWS\javace.exe
C:\WINDOWS\msgx32.exe
C:\WINDOWS\atlgr32.exe
C:\WINDOWS\atlzr32.exe
C:\WINDOWS\winpy32.exe
C:\WINDOWS\crjo.exe
C:\WINDOWS\crqg32.exe
C:\WINDOWS\javazk32.exe
C:\WINDOWS\netkw32.exe
C:\WINDOWS\crfm32.exe
C:\WINDOWS\javatb.exe
C:\WINDOWS\netgt32.exe
C:\WINDOWS\netdn32.exe
C:\WINDOWS\crzn.exe
C:\WINDOWS\appid32.exe
C:\WINDOWS\ipzq32.exe
C:\WINDOWS\appat.exe
C:\WINDOWS\d3ob.exe
C:\WINDOWS\ieyj32.exe
C:\WINDOWS\apidb.exe
C:\WINDOWS\crxd32.exe
C:\WINDOWS\sysnq.exe
C:\WINDOWS\system32\yfwhf.dll
C:\WINDOWS\system32\msis32.dll
C:\WINDOWS\system32\msmd32.exe
C:\WINDOWS\System32\gxyd.exe
C:\WINDOWS\system32\msiv32.exe
C:\WINDOWS\system32\addxb.exe
C:\WINDOWS\system32\crcf.exe
C:\WINDOWS\system32\msuk.exe
C:\WINDOWS\system32\sdkup32.exe
C:\WINDOWS\system32\winbo32.exe
C:\WINDOWS\system32\javaof.exe
C:\WINDOWS\system32\atlyc.exe
C:\WINDOWS\system32\netnb.exe
C:\WINDOWS\system32\atlfn.exe
C:\WINDOWS\system32\addws.exe
C:\WINDOWS\system32\crtt.exe
C:\WINDOWS\system32\d3yi.exe
C:\WINDOWS\system32\sysrj.exe
C:\WINDOWS\system32\mfccf.exe
C:\WINDOWS\system32\ntit32.exe
C:\WINDOWS\system32\msxn32.exe
C:\WINDOWS\system32\ipgu32.exe
C:\WINDOWS\system32\ipmn32.exe
C:\WINDOWS\system32\sysfp32.exe
C:\WINDOWS\system32\apiae32.exe
C:\WINDOWS\system32\ntzl.exe
C:\WINDOWS\system32\addky.exe
C:\WINDOWS\system32\apigk32.exe
C:\WINDOWS\system32\atlhk.exe
C:\WINDOWS\system32\d3qy.exe
C:\WINDOWS\system32\netgc.exe
C:\WINDOWS\system32\sysar.exe
C:\WINDOWS\system32\apinn32.exe
C:\WINDOWS\system32\winig32.exe
C:\WINDOWS\system32\ieoz.exe
C:\WINDOWS\system32\ieqc32.exe
C:\WINDOWS\system32\mskg32.exe
C:\WINDOWS\system32\javawb.exe
C:\WINDOWS\system32\sysxo.exe
C:\WINDOWS\system32\atlfd32.exe
C:\WINDOWS\system32\appoy32.exe
C:\WINDOWS\system32\crgk32.exe
C:\WINDOWS\system32\javaqi.exe
C:\WINDOWS\system32\sdkbv32.exe
C:\WINDOWS\system32\d3qh.exe
C:\WINDOWS\system32\netpp32.exe
C:\WINDOWS\system32\javauo32.exe
C:\WINDOWS\system32\netmq.exe
C:\WINDOWS\system32\apiuy32.exe
C:\WINDOWS\system32\iehp.exe
C:\WINDOWS\system32\apiob32.exe
C:\WINDOWS\system32\sdkmi.exe
C:\WINDOWS\system32\sysmc.exe
C:\WINDOWS\system32\ipse32.exe
C:\WINDOWS\system32\nthr.exe
C:\WINDOWS\system32\sdkal.exe
C:\WINDOWS\system32\d3do32.exe
C:\WINDOWS\system32\apist.exe
C:\WINDOWS\system32\d3km32.exe
C:\WINDOWS\system32\crmn32.exe
C:\WINDOWS\system32\sdkth.exe
C:\WINDOWS\system32\netiq.exe
C:\WINDOWS\system32\sdkgd.exe
C:\WINDOWS\system32\apiiz32.exe
C:\WINDOWS\system32\crzy32.exe
C:\WINDOWS\system32\ntiu.exe
C:\WINDOWS\system32\d3xp.exe
C:\WINDOWS\system32\ntaz32.exe
C:\WINDOWS\system32\mfcls32.exe
C:\WINDOWS\system32\apife32.exe
C:\WINDOWS\system32\craw.exe
C:\WINDOWS\system32\mfcdw32.exe
C:\WINDOWS\system32\d3xg.exe
C:\WINDOWS\system32\apiei.exe
C:\WINDOWS\system32\ipgx32.exe
C:\WINDOWS\system32\iesc32.exe
C:\WINDOWS\system32\iehf.exe
C:\WINDOWS\system32\ipvy32.exe
C:\WINDOWS\system32\crsj.exe
C:\WINDOWS\system32\apimk32.exe
C:\WINDOWS\system32\crua32.exe
C:\WINDOWS\system32\sysud.exe
C:\WINDOWS\system32\apicp.exe
C:\WINDOWS\system32\adddz.exe
C:\WINDOWS\system32\mfcxi32.exe
C:\Documents and Settings\Ashley\Application Data\raau.exe



8. Double click AboutBuster.exe that you downloaded earlier. Click OK, click Start, then click OK. This will scan your computer for the bad files and delete them. Save the report(copy and paste into notepad or wordpad and save as a .txt file) and post a copy back here when you are done with all the steps.

9. Scan with Adaware and let it remove any bad files found.

10. Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

11. Reboot to normal mode, scan again with Hijack This and post a new log here.

12. Finally, do an online scan HERE. Let it remove any infected files found.


Post a fresh HijackThis log and the AboutBuster report back here please.

Still there is way to go


--------------------

::mmxx66::

#7 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 25 July 2004 - 03:20 PM

sorry about the problems but unfortunatly i have never heard of a program called 'About Buster'.

You should really read what I write...

In my first response I said:

Next, download About:Buster from here

http://www.downloads...AboutBuster.zip



As for what someone else advised you to do....
If you don't mind I'd like to do it one way only, or we're never going to get you fixed....

As for the script, it ought to run, providing you saved it correctly...
However, I suggest we forget about it; please follow the directions exacrly the way I gave them to you in my first reply:

end task on and delete files > run Hijack This to fix the items I rendered in bold.

Download About:Buster > Safe Mode, run it, CoolWebShredder, etcetera...

Providing you follow directions carefully I promise we'll get this fixed.

Edited by TonyKlein, 25 July 2004 - 03:21 PM.


#8 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 25 July 2004 - 06:33 PM

ok mate, i will follow your instructions. But i dont have the files 'R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049' and 'R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049'. So i cant fix them before i run auto-buster. My main page is 'C:\Windows\Secure'.

#9 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 26 July 2004 - 05:41 AM

I'm quoting from the log you posted; those are the lines exacly the way they are rendered in Hijack This. I figure that if I can see them, you should be able to as well; unless the situation has changed of course...

- HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://yfwhf.dll/index.html#37049
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\yfwhf.dll/sp.html#37049
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank


But never mind, run About:buster nevertheless....

Edited by TonyKlein, 26 July 2004 - 05:42 AM.


#10 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 26 July 2004 - 08:24 AM

hi. I encountered 1 problem during my process. Nevertheless my homepage trojan has now gone and it only takes seconds to log my acount into windows unlike before where it took about 5 minutes.

The problem that i faced is whenever i clicked 'free virus scan' at http://housecall.trendmicro.com a windows error message appeared. The message is familier to me as it is the one that says 'Send error report' or 'Dont send error report'. So because of this i am unable to scan my computer from this location.

My new hijack this log is:

Logfile of HijackThis v1.97.7
Scan saved at 14:09:47, on 26/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\sm56hlpr.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\imapi.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [MoneyStartUp10.0] "C:\Program Files\Microsoft Money\System\Activation.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Money Viewer (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38188.580787037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab


Even though i can now reset my IE homepage the hijack this log still says my default and local page is C:\WINDOWS\secure.html. Also this quote is quite bizzarre as i have deleted the file:

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe



Thank you very much for your help and patience so far.

#11 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 26 July 2004 - 08:31 AM

I think we're getting there; with all browser windows closed, have Hijack This fix the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\secure.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\secure.html

O2 - BHO: (no name) - {5DA69830-91DD-A25B-F3C5-BD9CDB0ADEE7} - C:\WINDOWS\system32\msis32.dll (file missing)

O4 - HKLM\..\Run: [msmd32.exe] C:\WINDOWS\system32\msmd32.exe


Now restart your computer, and post a fresh log

#12 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 26 July 2004 - 09:33 AM

here is my new log.


Logfile of HijackThis v1.97.7
Scan saved at 15:32:01, on 26/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\sm56hlpr.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe
C:\Program Files\iPod\bin\iPodService.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\Ashley\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {C52F1B4D-A771-445D-A3D8-3F1E4B7B11F8} - C:\WINDOWS\System32\mff.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38188.580787037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#13 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 26 July 2004 - 09:34 AM

My default homepage is no longer C:\WINDOWS\secure.html. Thanks.

#14 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 27 July 2004 - 12:34 PM

I was expecting a reply so now i understand that it is fixed i would like to let you know that i am very grateful and thankful. Its good to know that people like you are giving up your time to help others. Best wishes mate.

#15 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 28 July 2004 - 03:27 AM

I'm afraid you're now infected by another CoolWebSearch variant, that's isn't easy to remove either....

Click here to download FindnFix.exe by Freeatlast.

Double-click on the FINDnFIX.exe and it will install a folder called FINDnFIX on your system. Go to that folder and double-click on !LOG!.bat. The program will take a few minutes to collect the necessary information. When done post the contents of Log.txt in this thread.

#16 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 30 July 2004 - 05:05 AM

Here is my FindFix log:


»»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»»
»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q823353-Q832894
The type of the file system is NTFS.
C: is not dirty.

Fri 30 Jul 04 11:03:14
11:03am up 0 days, 0:33

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»
The list will produce a small database of files that will match certain criteria.
You must know how to ID the file based on the filters provided in
the scan, as not all the files flagged are bad.
Ex: read only files, s/h files, last modified date. size, etc.
The filters provided should help narrow down the list, and hopefully
pinpoint the culprit.
Along with that,registry scan logged at the end should match the
corresponding file(s) listed.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Unless the file match the entire criteria, it should not be pointed to remove
without attempting to confirm it's nature!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!
If in doubt, always search the file(s) and properties according to criteria!

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder
»»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/27)»»»»»»»»»»»»»»»»

»»»*»»»*Use at your own risk!»»»*»»»*

Scanning for file(s)...
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»» (*1*) »»»»» .........
»»Locked or 'Suspect' file(s) found...

C:\WINDOWS\System32\CTLC.DLL +++ File read error
\\?\C:\WINDOWS\System32\CTLC.DLL +++ File read error

»»»»» (*2*) »»»»»........
CTLC.DLL Can't Open!

»»»»» (*3*) »»»»»........

C:\WINDOWS\SYSTEM32\
ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

unknown/hidden files...

No matches found.

»»»»» (*4*) »»»»».........
Sniffing..........
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL

»»»»»(*5*)»»»»»
¯ Access denied ® ..................... CTLC.DLL .....57344 20.07.2004

»»»»»(*6*)»»»»»
fgrep: can't open input C:\WINDOWS\SYSTEM32\CTLC.DLL

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»»Search by size...


C:\WINDOWS\SYSTEM32\
ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

No matches found.

No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448

»»Dumping Values........
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***)

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(NI) ALLOW Read BUILTIN\Users
(IO) ALLOW Read BUILTIN\Users
(NI) ALLOW Read BUILTIN\Power Users
(IO) ALLOW Read BUILTIN\Power Users
(NI) ALLOW Full access BUILTIN\Administrators
(IO) ALLOW Full access BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access BUILTIN\Administrators
(IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Read BUILTIN\Power Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM


»»Member of...: (Admin logon required!)
User is a member of group WILKINSON\None.
User is a member of group \Everyone.
User is a member of group BUILTIN\Administrators.
User is a member of group BUILTIN\Users.
User is a member of group \LOCAL.
User is a member of group NT AUTHORITY\INTERACTIVE.
User is a member of group NT AUTHORITY\Authenticated Users.


»»»»»»Backups created...»»»»»»
11:04am up 0 days, 0:34
Fri 30 Jul 04 11:04:17

A C:\FINDnFIX\keyback.hiv
--a-- - - - - - 8,192 07-30-2004 keyback.hiv
A C:\FINDnFIX\keys1\winkey.reg
--a-- - - - - - 287 07-30-2004 winkey.reg
*Temp backups...
.
..
keyback2.hi_
winkey2.re_


C:\FINDNFIX\
JUNKXXX Fri 30 Jul 2004 11:03:14 .D... <Dir>

1 item found: 0 files, 1 directory.

»»Performing string scan....
00001150: ?
00001190: vk UDeviceNo
000011D0:tSelectedTimeout 1 5 @ vk ' z
00001210:GDIProcessHandleQuota" 9 0 | vk X
00001250:Spooler2 y e s n vk =pswapdisk
00001290: 8 h vk ( R TransmissionRetryTimeout
000012D0: vk ' n USERProcessHandleQuotai 8
00001310:h vk : H [ AppInit_DLLsvk C :
00001350:\ W I N D O W S \ S y s t e m 3 2 \ c t l c . d l l d x
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
00001590:
000015D0:

---------- WIN.TXT
AppInit_DLLsvk
--------------
--------------
$011C7: UDeviceNotSelectedTimeout
$0120F: zGDIProcessHandleQuota
$012B8: TransmissionRetryTimeout
$012E8: USERProcessHandleQuotai
$01338: AppInit_DLLsvk
--------------
--------------
C:\WINDOWS\System32\ctlc.dll
--------------
--------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"=""

A handle was successfully obtained for the
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.
This key has 0 subkeys.
The AppInitDLLs value exists and reports as 58 bytes, including the 2 for string termination.

[AppInitDLLs]
Ansi string : "C:\WINDOWS\System32\ctlc.dll"
0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O.
0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e.
0020 6d 00 33 00 32 00 5c 00 63 00 74 00 6c 00 63 00 | m.3.2.\.c.t.l.c.
0030 2e 00 64 00 6c 00 6c 00 00 00 | ..d.l.l...


#17 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 30 July 2004 - 05:06 AM

Here is my findfix log:


»»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»»»
»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q823353-Q832894
The type of the file system is NTFS.
C: is not dirty.

Fri 30 Jul 04 11:03:14
11:03am up 0 days, 0:33

»»»»»»»»»»»»»»»»»»*** Note! ***»»»»»»»»»»»»»»»»
The list will produce a small database of files that will match certain criteria.
You must know how to ID the file based on the filters provided in
the scan, as not all the files flagged are bad.
Ex: read only files, s/h files, last modified date. size, etc.
The filters provided should help narrow down the list, and hopefully
pinpoint the culprit.
Along with that,registry scan logged at the end should match the
corresponding file(s) listed.
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Unless the file match the entire criteria, it should not be pointed to remove
without attempting to confirm it's nature!
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
At times there could be several (legit) files flagged, and/or duplicate culprit file(s)!
If in doubt, always search the file(s) and properties according to criteria!

The file(s) found should be moved to \FINDnFIX\"junkxxx" Subfolder
»»»»»»»»»»»»»»»»»»***LOG!***(*updated 7/27)»»»»»»»»»»»»»»»»

»»»*»»»*Use at your own risk!»»»*»»»*

Scanning for file(s)...
»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»» (*1*) »»»»» .........
»»Locked or 'Suspect' file(s) found...

C:\WINDOWS\System32\CTLC.DLL +++ File read error
\\?\C:\WINDOWS\System32\CTLC.DLL +++ File read error

»»»»» (*2*) »»»»»........
CTLC.DLL Can't Open!

»»»»» (*3*) »»»»»........

C:\WINDOWS\SYSTEM32\
ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

unknown/hidden files...

No matches found.

»»»»» (*4*) »»»»».........
Sniffing..........
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL

»»»»»(*5*)»»»»»
¯ Access denied ® ..................... CTLC.DLL .....57344 20.07.2004

»»»»»(*6*)»»»»»
fgrep: can't open input C:\WINDOWS\SYSTEM32\CTLC.DLL

»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»*»»»
»»»»»Search by size...


C:\WINDOWS\SYSTEM32\
ctlc.dll Tue 20 Jul 2004 20:59:02 A...R 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

No matches found.

No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\WINDOWS\SYSTEM32\CTLC.DLL
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 448

»»Dumping Values........
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs = (*** MISSING TRAILING NULL CHARACTER ***)

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(NI) ALLOW Read BUILTIN\Users
(IO) ALLOW Read BUILTIN\Users
(NI) ALLOW Read BUILTIN\Power Users
(IO) ALLOW Read BUILTIN\Power Users
(NI) ALLOW Full access BUILTIN\Administrators
(IO) ALLOW Full access BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access BUILTIN\Administrators
(IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
Read BUILTIN\Power Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM


»»Member of...: (Admin logon required!)
User is a member of group WILKINSON\None.
User is a member of group \Everyone.
User is a member of group BUILTIN\Administrators.
User is a member of group BUILTIN\Users.
User is a member of group \LOCAL.
User is a member of group NT AUTHORITY\INTERACTIVE.
User is a member of group NT AUTHORITY\Authenticated Users.


»»»»»»Backups created...»»»»»»
11:04am up 0 days, 0:34
Fri 30 Jul 04 11:04:17

A C:\FINDnFIX\keyback.hiv
--a-- - - - - - 8,192 07-30-2004 keyback.hiv
A C:\FINDnFIX\keys1\winkey.reg
--a-- - - - - - 287 07-30-2004 winkey.reg
*Temp backups...
.
..
keyback2.hi_
winkey2.re_


C:\FINDNFIX\
JUNKXXX Fri 30 Jul 2004 11:03:14 .D... <Dir>

1 item found: 0 files, 1 directory.

»»Performing string scan....
00001150: ?
00001190: vk UDeviceNo
000011D0:tSelectedTimeout 1 5 @ vk ' z
00001210:GDIProcessHandleQuota" 9 0 | vk X
00001250:Spooler2 y e s n vk =pswapdisk
00001290: 8 h vk ( R TransmissionRetryTimeout
000012D0: vk ' n USERProcessHandleQuotai 8
00001310:h vk : H [ AppInit_DLLsvk C :
00001350:\ W I N D O W S \ S y s t e m 3 2 \ c t l c . d l l d x
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:
00001590:
000015D0:

---------- WIN.TXT
AppInit_DLLsvk
--------------
--------------
$011C7: UDeviceNotSelectedTimeout
$0120F: zGDIProcessHandleQuota
$012B8: TransmissionRetryTimeout
$012E8: USERProcessHandleQuotai
$01338: AppInit_DLLsvk
--------------
--------------
C:\WINDOWS\System32\ctlc.dll
--------------
--------------
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"AppInit_DLLs"=""

A handle was successfully obtained for the
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key.
This key has 0 subkeys.
The AppInitDLLs value exists and reports as 58 bytes, including the 2 for string termination.

[AppInitDLLs]
Ansi string : "C:\WINDOWS\System32\ctlc.dll"
0000 43 00 3a 00 5c 00 57 00 49 00 4e 00 44 00 4f 00 | C.:.\.W.I.N.D.O.
0010 57 00 53 00 5c 00 53 00 79 00 73 00 74 00 65 00 | W.S.\.S.y.s.t.e.
0020 6d 00 33 00 32 00 5c 00 63 00 74 00 6c 00 63 00 | m.3.2.\.c.t.l.c.
0030 2e 00 64 00 6c 00 6c 00 00 00 | ..d.l.l...


#18 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 30 July 2004 - 10:34 AM

sorry about the delay. i hope you find this and continue helping.

#19 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 30 July 2004 - 01:20 PM

OK, C:\Windows\System32\ctlc.dll is the super-hidden installer that will keep restoring this hijack at boot unless it's removed.

As the next step, DISABLE your antivirus and keep it disabled untill we've finished removing this one; if you do not, it may interfere.

Now in the FindnFix 'keys1' folder, double click on FIX.bat. You will get an alert of about 15 seconds before reboot - allow it to reboot.

On restart, open Explorer and navigate to C:\Windows\System32 folder, find the ctlc.dll file (it should be visible now). RightClick on ctlc.dll , and select -> Cut from the menu.

Immediately Open the C:\FINDnFIX\junkxxx subfolder.
RightClick inside it and select 'Paste' from the menu; hit 'ok' when/if asked on 'read only' file move prompt.

- Make sure the file is now indeed in that Junkxxx subfolder

Open the FINDnFIX folder again and run the "Restore.bat" file.
It will run and generate a log (log2.txt) . Post the contents of that log in your reply.

#20 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 01 August 2004 - 12:37 PM

»»»»»»»»*** www10.brinkster.com/expl0iter/freeatlast/FNF/ ***»»»»»»»

Sun 01 Aug 04 18:33:11
6:33pm up 0 days, 0:02

Microsoft Windows XP [Version 5.1.2600]
»»»IE build and last SP(s)
6.0.2800.1106 SP1-Q823353-Q832894
The type of the file system is NTFS.
C: is not dirty.

»»»»»»»»»»»»»»»»»»***LOG2!(*updated 7/27)***»»»»»»»»»»»»»»»»

This log will confirm if the file was successfully moved, and/or
the right file was selected...

Scanning for file(s) in System32...

»»»»»»» (1) »»»»»»»

»»»»»»» (2) »»»»»»»

»»»»»»» (3) »»»»»»»

No matches found.
Unknown/hidden files...

No matches found.

»»»»»»» (4) »»»»»»»
Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»»»»(5)»»»»»

»»»»»(6)»»»»»

»»»»»»» Search by size...


No matches found.

No matches found.

No matches found.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


»»»*»»» Scanning for moved file... »»»*»»»

* result\\?\C:\FINDnFIX\junkxxx\CTLC.222


C:\FINDNFIX\JUNKXXX\
ctlc.222 Tue 20 Jul 2004 20:59:02 A.... 57,344 56.00 K

1 item found: 1 file, 0 directories.
Total of file sizes: 57,344 bytes 56.00 K

Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

Sniffed -> C:\FINDNFIX\JUNKXXX\CTLC.222

**File C:\FINDNFIX\JUNKXXX\CTLC.222
0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami
0000DED3: 63 65 53 65 74 75 70 00 . 32 00 00 00 00 00 E0 01 ceSetup. 2.....à.

A----- CTLC .222 0000E000 20:59.02 20/07/2004

--a-- W32i - - - - 57,344 07-20-2004 ctlc.222
A C:\FINDnFIX\junkxxx\ctlc.222

CHK-SAFE.EXE Ver 2.51 by Bill Lambdin Don Peters and Robert Bullock.
MD5 Message Digest Algorithm by RSA Data Security, Inc.

File name Size Date Time MD5 Hash
________________________________________________________________________
CTLC.222 57344 07-20-104 20:59 c185b36f9969d3a6d2122ba7cbc02249

CRC-Cyclic Redundancy Checker, Version 1.20, 08-Feb-92, rtk

C:\FINDNFIX\JUNKXXX
CTLC.222 : crc16=3138 crc32=D5C9FB2E


File: <C:\FINDnFIX\junkxxx\ctlc.222>

CRC-32 : D5C9FB2E

MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249




#######################################################
*Known files are...
--------------------
File: ((56k; (57,344 bytes)
CRC16 : 3138
CRC-32 : D5C9FB2E
MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249
--------------------
File: ((35k; (35,840 bytes)
CRC16 : EEB1
CRC-32 : 33081C8B
MD5 : 1DE9A8E2 4C826006 7A479B09 577D9CAE
--------------------
File: ((21k; (21,504 bytes)
CRC16 : 90A5
CRC-32 : 2258F59E
MD5 : EFEE2CB3 B342A351 51802356 9637F8E6
#######################################################
»»Permissions:
C:\FINDnFIX\junkxxx\ctlc.222 Everyone:F
BUILTIN\Administrators:F
BUILTIN\Administrators:F
BUILTIN\Administrators:F
BUILTIN\Administrators:F
NT AUTHORITY\SYSTEM:F
WILKINSON\Ashley:F
BUILTIN\Users:R

Directory "C:\FINDnFIX\junkxxx\."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000002 tc-- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000009 --o- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000002 tc-- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000009 --o- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000013 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000013 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000010 t--- 001F01FF ---- DSPO rw+x WILKINSON\Ashley
Allow 0000001B -co- 10000000 ---A ---- ---- \CREATOR OWNER
Allow 00000013 tco- 001200A9 ---- -S-- r--x BUILTIN\Users
Allow 00000012 tc-- 00000004 ---- ---- --+- BUILTIN\Users
Allow 00000012 tc-- 00000002 ---- ---- -w-- BUILTIN\Users

Owner: WILKINSON\Ashley

Primary Group: WILKINSON\None

Directory "C:\FINDnFIX\junkxxx\.."
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000003 tco- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000003 tco- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000000 t--- 001F01FF ---- DSPO rw+x WILKINSON\Ashley
Allow 0000000B -co- 10000000 ---A ---- ---- \CREATOR OWNER
Allow 00000003 tco- 001200A9 ---- -S-- r--x BUILTIN\Users
Allow 00000002 tc-- 00000004 ---- ---- --+- BUILTIN\Users
Allow 00000002 tc-- 00000002 ---- ---- -w-- BUILTIN\Users

Owner: WILKINSON\Ashley

Primary Group: WILKINSON\None

File "C:\FINDnFIX\junkxxx\ctlc.222"
Permissions:
Type Flags Inh. Mask Gen. Std. File Group or User
======= ======== ==== ======== ==== ==== ==== ================
Allow 00000000 t--- 001F01FF ---- DSPO rw+x \Everyone
Allow 00000000 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000000 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000000 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000010 t--- 001F01FF ---- DSPO rw+x BUILTIN\Administrators
Allow 00000010 t--- 001F01FF ---- DSPO rw+x NT AUTHORITY\SYSTEM
Allow 00000010 t--- 001F01FF ---- DSPO rw+x WILKINSON\Ashley
Allow 00000010 t--- 001200A9 ---- -S-- r--x BUILTIN\Users

Owner: WILKINSON\Ashley

Primary Group: WILKINSON\None

C:\FINDnFIX\junkxxx\ctlc.222;Everyone:RrRaRepWwAWaWePXDDcO
C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO
C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO
C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO
C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Administrators:RrRaRepWwAWaWePXDDcO[I]
C:\FINDnFIX\junkxxx\ctlc.222;NT AUTHORITY\SYSTEM:RrRaRepWwAWaWePXDDcO[I]
C:\FINDnFIX\junkxxx\ctlc.222;WILKINSON\Ashley:RrRaRepWwAWaWePXDDcO[I]
C:\FINDnFIX\junkxxx\ctlc.222;BUILTIN\Users:RrRaRepX[I]



»»Size of Windows key:
(*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

»»Dumping Values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
DeviceNotSelectedTimeout = 15
GDIProcessHandleQuota = REG_DWORD 0x00002710
Spooler = yes
swapdisk =
TransmissionRetryTimeout = 90
USERProcessHandleQuota = REG_DWORD 0x00002710
AppInit_DLLs =

»»Security settings for 'Windows' key:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright © 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW QWCEN-DS-- BUILTIN\Power Users
(ID-IO) ALLOW QWCEN-DS-- BUILTIN\Power Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Full access WILKINSON\Ashley
(ID-IO) ALLOW Full access CREATOR OWNER

Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
Read BUILTIN\Users
QWCEN-DS-- BUILTIN\Power Users
Full access BUILTIN\Administrators
Full access NT AUTHORITY\SYSTEM
Full access WILKINSON\Ashley



00001150: $ ? 1 <w#_ck
00001190: 1 <w#_ck 1 <w#_ck
000011D0: vk S DeviceNotSelectedTimeout 1 5
00001210: l d vk ' UGDIProcessHandleQuotaout
00001250: 9 0 | vk zSpoolere y e s @
00001290: vk swapdisk ` vk
000012D0: P TransmissionRetryTimeout vk ' is
00001310:USERProcessHandleQuota~ ` H vk
00001350: j AppInit_DLLs m~
00001390:
000013D0:
00001410:
00001450:
00001490:
000014D0:
00001510:
00001550:

---------- NEWWIN.TXT
AppInit_DLLsˆm~
--------------
--------------
$011F0: DeviceNotSelectedTimeout
$01237: UGDIProcessHandleQuotaout
$012E0: TransmissionRetryTimeout
$0130E: isUSERProcessHandleQuota
$01360: AppInit_DLLs
--------------
--------------
No strings found.


d.... 0 Jul 30 11:03 .
d.... 0 Jul 30 11:03 ..
....a 57344 Jul 20 20:59 ctlc.222

3 files found occupying 55296 bytes

-------- C:\FINDNFIX\JUNKXXX\CTLC.222
InstallStreamingDeviceStreamingDeviceSetupStreamingDeviceSetup2
===============================================================================
57,344 bytes 5,734,400 cps
Files: 1 Records: 13,139 Matches: 3 Elapsed Time: 00:00:00.01

VDIR v1.00
Path: C:\FINDNFIX\JUNKXXX\*.*
---------------------------------------+---------------------------------------
. <dir> 07-30-:4 11:03|CTLC 222 57344 A 07-20-:4 20:59
.. <dir> 07-30-:4 11:03|
---------------------------------------+---------------------------------------
3 files totaling 57344 bytes consuming 65024 bytes of disk space.
17299968 bytes available on Drive C: No volume label

...File dump...

56880 00000000 4b45524e 454c3332 2e444c4c |....KERNEL32.DLL| 0de30
56896 00004c6f 61644c69 62726172 79410000 |..LoadLibraryA..| 0de40
56912 47657450 726f6341 64647265 73730000 |GetProcAddress..| 0de50
56928 00000000 00000000 00000000 a6f00100 |................| 0de60
56944 01000000 03000000 03000000 88f00100 |................| 0de70
56960 94f00100 a0f00100 05270000 9a230000 |.........'...#..| 0de80
56976 242a0000 a7f00100 bef00100 d3f00100 |$*..............| 0de90
56992 00000100 02000049 6e737461 6c6c5374 |.......InstallSt| 0dea0
57008 7265616d 696e6744 65766963 65005374 |reamingDevice.St| 0deb0
57024 7265616d 696e6744 65766963 65536574 |reamingDeviceSet| 0dec0
57040 75700053 74726561 6d696e67 44657669 |up.StreamingDevi| 0ded0
57056 63655365 74757032 |ceSetup2 | 0dee0

Detecting...

C:\FINDnFIX\junkxxx
ctlc.222 ACL has 8 ACE(s)
SID = /Everyone S-1-1-0
ACE 0 is an ACCESS_ALLOWED_ACE_TYPE
ACE 0 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Administrators S-1-5-32-544
ACE 1 is an ACCESS_ALLOWED_ACE_TYPE
ACE 1 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Administrators S-1-5-32-544
ACE 2 is an ACCESS_ALLOWED_ACE_TYPE
ACE 2 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Administrators S-1-5-32-544
ACE 3 is an ACCESS_ALLOWED_ACE_TYPE
ACE 3 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Administrators S-1-5-32-544
ACE 4 is an ACCESS_ALLOWED_ACE_TYPE
ACE 4 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = NT AUTHORITY/SYSTEM S-1-5-18
ACE 5 is an ACCESS_ALLOWED_ACE_TYPE
ACE 5 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = WILKINSON/Ashley S-1-5-21-823518204-2000478354-1801674531-1003
ACE 6 is an ACCESS_ALLOWED_ACE_TYPE
ACE 6 mask = 0x001f01ff -R -W -X -D -DEL_CHILD -CHANGE_PERMS -TAKE_OWN
SID = BUILTIN/Users S-1-5-32-545
ACE 7 is an ACCESS_ALLOWED_ACE_TYPE
ACE 7 mask = 0x001200a9 -R -X
ACL done...


Finished Detecting... 

#21 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 01 August 2004 - 03:09 PM

Well done! :)

Open the FINDnFIX folder again and open the Files2 folder. Double-click on the ZIPZAP.bat. It will quickly clean the rest and will make a copy of the bad file(s) in the same folder (junkxxx.zip) and open your email client with instructions.

Simply drag and drop the junkxxx.zip file from the folder into the mail message and submit to the specified addresses.
Please be sure to include a link to this thread in the body of your email. Reboot when done, then delete the entire FINDnFIX folder.

Now click here to download CWShredder by Merijn Bellekom and run it, hit 'fix' as opposed to 'scan only'.
If you already have CWShredder, click 'Check for update' and make sure you are running version 1.59.1 .Reboot when done. Rescan with Hijack This, and post a new log in your next reply.

#22 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 01 August 2004 - 04:14 PM

:-) we are getting there!

Logfile of HijackThis v1.97.7
Scan saved at 22:14:06, on 01/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\sm56hlpr.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38188.580787037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gbn298.exe

#23 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 01 August 2004 - 05:15 PM

With all Browser Windows closed, have Hijack This fix these items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank

O16 - DPF: {FFFF0003-0001-101A-A3C9-08002B23E0CC} - http://direct.data-line.us/gbn298.exe


Go to Control Panel > Internet (Options)

In the General Tab > Temporary Internet Files section, hit "delete files". Make sure the 'delete all offline content' box is checked as well.

Now go to the 'Programs' tab, and click 'reset Web Settings'. In the dialog box, make sure 'Also reset my home page' check box is ticked.
Then click Yes , then OK, and OK once more in order to apply the settings.

Restart your computer, run Hijack This again, and post a fresh log.

#24 ashwilkinson

ashwilkinson

    Member

  • Full Member
  • Pip
  • 19 posts

Posted 02 August 2004 - 08:06 AM

here is my new log:


Logfile of HijackThis v1.97.7
Scan saved at 14:05:33, on 02/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\RunDll32.exe
C:\WINDOWS\System32\sm56hlpr.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Ashley\My Documents\hijack this\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SM56ACL] sm56hlpr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...38188.580787037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab

#25 TonyKlein

TonyKlein

    Forum Deity

  • Expert
  • PipPipPipPipPip
  • 1,841 posts

Posted 02 August 2004 - 12:01 PM

Clean log; happy surfing! :)

#26 dave38

dave38

    Devout Murphyite!

  • Emeritus
  • PipPipPipPipPip
  • 8,508 posts

Posted 02 August 2004 - 01:45 PM

Glad we could help!

If you need this topic reopened, please request this by sending the moderating team an email with the address of the thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
Be wary of strong drink. It may make you shoot at tax collectors, and miss!
Please support SWI forum




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button