Author Topic: cyanide rose's HijackThis log  (Read 4484 times)

0 Members and 1 Guest are viewing this topic.

Offline cyanide rose

  • Newbie
  • *
  • Posts: 13
cyanide rose's HijackThis log
« on: September 17, 2006, 05:56:57 PM »
Logfile of HijackThis v1.99.1
Scan saved at 3:52:53 AM, on 9/18/2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\COMMON~1\DOBE~1\ping.exe
C:\WINDOWS\??sembly\w?wexec.exe
E:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\cool.exe
C:\WINDOWS\slrundll.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {8596FC60-68DE-132E-F1A8-671335AE69E3} - C:\WINDOWS\System32\fuoqvhv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Dret] "C:\PROGRA~1\COMMON~1\DOBE~1\ping.exe" -vt yazb
O4 - HKCU\..\Run: [Skw] C:\WINDOWS\??sembly\w?wexec.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: Free WebSite Tools.lnk = ?
O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{35367287-C957-459E-B71D-EAAFEB38169B}: NameServer = 203.12.160.35 203.12.160.36
O17 - HKLM\System\CCS\Services\Tcpip\..\{DD932E68-6C9B-4963-9D7E-E447AE5C4ACA}: NameServer = 10.0.0.1,10.0.0.10
O17 - HKLM\System\CS1\Services\Tcpip\..\{35367287-C957-459E-B71D-EAAFEB38169B}: NameServer = 203.12.160.35 203.12.160.36
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe

I've downloaded and run Spybot, which got rid of a lot of nasties. Running Ad-Aware has caused my computer to shut itself down since it became infected yesterday. Also already done the Smitfraud fix previously with the following log:

SmitFraudFix v2.90

Scan done at 22:14:49.71, Sun 09/17/2006
Run from C:\Documents and Settings\sarah ann\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\.protected Deleted
C:\WINDOWS\system32\ishost.exe Deleted
C:\WINDOWS\system32\ismini.exe Deleted
C:\WINDOWS\system32\isnotify.exe Deleted
C:\WINDOWS\system32\issearch.exe Deleted
C:\WINDOWS\system32\ixt?.dll Deleted
C:\WINDOWS\system32\ot.ico Deleted
C:\WINDOWS\system32\ts.ico Deleted
C:\WINDOWS\system32\components\flx?.dll Deleted
C:\DOCUME~1\SARAHA~1\STARTM~1\Programs\Startup\.protected Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\.protected Deleted
C:\Program Files\Safety Bar\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
Registry Cleaning done.
 
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



I'm still getting script error pop ups randomly when going onto to various web sites and I keep getting disconnected from my own connection with something dialing up to 'CoolWeb'  and other bogus connections instead.

If anyone could help me out, it'd be greaty appreciated. Thank you in advance. :)


Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: cyanide rose's HijackThis log
« Reply #1 on: September 17, 2006, 07:11:45 PM »
    Hi, cyanide rose. :rose:   Welcome to LandzDown Forum.

    I suggest you copy the instructions to your desktop or print them as you will not have access to the internet while conducting most of the cleanup.

    A.  Download
ewido anti-spyware from HERE.  Save the file to your desktop so  you can locate it.
  • Locate the ewido anti-spyware icon on the desktop.
  • Double-click the large yellow "e" ewido icon to launch the set up program. 
  • The installation will require a restart of the computer.
Launch ewido to update to the latest definition files.
  • On the main screen select the "Update" icon
  • Click "Start Update".  The update will start and a progress bar will show the updates being installed.
  • If you have problems with the updater, you can use this link to manually update ewido --   ewido manual updates
B.  ewido settings
  • Select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • In the Settings screen click "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • DE-Select "Only if threats were found"
    • close ewido
C. Please uninstall the file shown below:
  •   Click "start" on the taskbar and then click on the "Control Panel" icon
  • Please double-click the "Add or Remove Programs" icon
  • A list of programs installed will be "populated" this may take a bit of time.
  • In this list please find C:\Program Files\Ultimate Defender
  • A wizard should then open, which will guide you through the uninstallation.
  • Delete the folder if not removed.
D. Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
E. Scanning and system cleaning with ewido. 
  • Lauch ewido-anti-spyware by double-clicking the icon on the desktop. IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan"
  • ewido will now begin the scanning process.  Be patient as this may take a little time.
  • While scanning, ewido will list any infections found on the left side.
  • When the scan is completed, the recommended action should be set to Quarantine.  If not click Recommended Action and set it there. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right side.
  • Click on "Save Report", then "Save Report As".  This will create a text file.  Make sure you know where to find this file again (like on the Desktop).
  • Close ewido.

F. I suggest you run SmitFraudFix again as I am seeing a couple of things in your HJT log that were shown as removed.

G. Start HijackThis, close all open windows leaving only HijackThis running. Place a check against the following, if found, and press "Fix Checked":

R3 - URLSearchHook: (no name) - {8596FC60-68DE-132E-F1A8-671335AE69E3} - C:\WINDOWS\System32\fuoqvhv.dll
O4 - HKLM\..\Run: [Ultimate Defender] "C:\Program Files\Ultimate Defender\App.exe" hide
O4 - HKCU\..\Run: [Dret] "C:\PROGRA~1\COMMON~1\DOBE~1\ping.exe" -vt yazb
O4 - HKCU\..\Run: [Skw] C:\WINDOWS\??sembly\w?wexec.exe
O4 - Startup: .protected
O4 - Global Startup: .protected
O4 - Global Startup: Free WebSite Tools.lnk = ?
O17 - HKLM\System\CCS\Services\Tcpip\..\{DD932E68-6C9B-4963-9D7E-E447AE5C4ACA}: NameServer = 10.0.0.1,10.0.0.10


I.  Restart in normal mode and download the Killbox © Option^Explicit.
Unzip it to the desktop

Double-click on Killbox.exe to run it. Place the following lines (complete paths) in bold in the "Full Path of File to Delete" box in Killbox, and click the red button with the white X on it after each

C:\WINDOWS\System32\fuoqvhv.dll
C:\WINDOWS\??sembly\w?wexec.exe

For these files, put a mark next to "Delete on Reboot". Copy and paste each file into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

If your computer does not restart automatically, please restart it manually.

J.  Double-click the HijackThis icon on your desktop.  Choose "Do a system scan and save logfile".  Please post it with your reply, as well as the ewido log and new Smitfraud log. 

Let me know how your system is doing.  Thanks.

[/list]
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline cyanide rose

  • Newbie
  • *
  • Posts: 13
Re: cyanide rose's HijackThis log
« Reply #2 on: September 18, 2006, 02:03:00 PM »
Hi Corrine, than you so much for helping. :)

My Ewido log:
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

 + Created at:   11:29:04 PM 9/18/2006

 + Scan result:   



C:\Program Files\Common Files\flbeleef\djpafpnd\acnbnpja.exe -> Adware.Gator : Cleaned with backup (quarantined).
C:\Program Files\Common Files\flbeleef\frhadcapce\ranpnllnj.exe -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\CMEIIAPI.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\CMESys.exe -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\CMEUpd.exe -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GController.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GDwldEng.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GFormCTM.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GIoclClient.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GStore.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GStoreServer.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GSvcMgr.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\CMEII\GSvcSAP.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\GMT\EGNSEngine.dll -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\GMT\GMT.exe -> Adware.Gator : Cleaned with backup (quarantined).
D:\Program Files\Common Files\GMT\egIEEngine.dll -> Adware.Gator : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fuoqvhv.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\аѕsembly\wοwexec.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\khfddcc.dll -> Adware.Virtumionde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rhasto.exe -> Backdoor.Agent.ec : Cleaned with backup (quarantined).
D:\Program Files\Jasc Software Inc\Paint Shop Pro 7\Psp 7.02 & Asp 3.02 Crack.exe -> Backdoor.Theef.111 : Cleaned with backup (quarantined).
C:\bla.exe -> Downloader.Small.aaq : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Application Data\IEService\v28.exe -> Dropper.VB.cd : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@maxis.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@newsinteractive.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@adtech[1].txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@adviva[2].txt -> TrackingCookie.Adviva : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@bfast[1].txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@com[1].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@com[2].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@commission-junction[1].txt -> TrackingCookie.Commission-junction : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@dbbsrv[2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@e-2dj6wjk4knd5wkq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@y-1shz2prbmdj6wvny-1sez2pra2dj6wfk4ajc5gfoaudj6x9ny-1seq-2-2.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkocgc5oeqq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@y-1shz2prbmdj6wvny-1sez2pra2dj6wjkyegdjacpgqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyagajalpqqdj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ads.euniverseads[1].txt -> TrackingCookie.Euniverseads : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@euniverseads[1].txt -> TrackingCookie.Euniverseads : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@a.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@as1.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@gator[1].txt -> TrackingCookie.Gator : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ehg-cafepress.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ehg-espn.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ehg-mtv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ehg-newsinternational.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ehg-usoc.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@hotlog[1].txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@linkbuddies[2].txt -> TrackingCookie.Linkbuddies : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@valueclick.ne[1].txt -> TrackingCookie.Ne : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@www.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@www1.paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@www.popuptraffic[1].txt -> TrackingCookie.Popuptraffic : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ads.specificpop[1].txt -> TrackingCookie.Specificpop : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@spylog[2].txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@fhm.valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@valueclick[3].txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@ads.x10[1].txt -> TrackingCookie.X10 : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Cookies\sarah ann@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@c1.zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
E:\Cookies\sarah ann@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Local Settings\Temporary Internet Files\Content.IE5\ODIJM38T\bgates[1].exe -> Trojan.Dialer.pz : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Local Settings\Temporary Internet Files\Content.IE5\G74RA1WZ\srvqnz[1].exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Local Settings\Temporary Internet Files\Content.IE5\INOXYLWJ\srvclb[1].exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cool.exe -> Trojan.Dialer.qs : Cleaned with backup (quarantined).
C:\Documents and Settings\sarah ann\Local Settings\Temporary Internet Files\Content.IE5\C9UJGPQJ\srvcfx[1].exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win9A.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\system32\enbiei.exe -> Worm.Lovesan.a : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mslaugh.exe -> Worm.Lovesan.a : Cleaned with backup (quarantined).
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\RBU1YZ0D\WksPatch[1].exe -> Worm.Welchia.b : Cleaned with backup (quarantined).


::Report end


My Smitfraud log:
SmitFraudFix v2.90

Scan done at 23:30:49.53, Mon 09/18/2006
Run from C:\Documents and Settings\sarah ann\Desktop\Spyware ****\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\.protected Deleted
C:\DOCUME~1\SARAHA~1\STARTM~1\Programs\Startup\.protected Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\.protected Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
 
Registry Cleaning done.
 
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


My HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 11:47:00 PM, on 9/18/2006
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\QuickTime\qttask.exe
E:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\realplay.exe" /RunUPGToolCommandReBoot
O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe

Now, I tried to use Killbox and copied & pasted the correct lines but was told that those files were already deleted. Coolweb, I think is still on the computer somewhere as it disconnected and hijacked the modem again. I did a search on Cool.exe and pressed shift + delete after that so I'm not sure where to go from here or if that did any good.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11530
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: cyanide rose's HijackThis log
« Reply #3 on: September 18, 2006, 03:55:59 PM »
Hi, cyanide rose.  First, I'd like you to update Sun Java, the older version being vulnerable for C:\WINDOWS\system32\khfddcc.dll that ewido removed.  The instructions are below.

I also want to be sure no Virtumundo pieces are hiding.  Thus, the second thing is to rename the HijackThis.exe.  Go to C:\Program Files\Hijackthis and open the folder.  Right-click on HijackThis.exe and select rename.  Name it what you wish -- something like OzHJT.exe ;) .

Next, you mentioned Coolweb, although I had not seen signs of CoolWebSearch on your computer.  But, just to be sure, please download Trend-Micro's CWShredder from http://www.trendmicro.com/ftp/products/online-tools/cwshredder.exe .  Save it to the desktop,  Open CWShredder and click on *check for updates*.  If any updates are found, please download and install them

Then, to run the tool, press the *Fix* Button (don't use the scan button).
The tool will run and remove any CWS infections found.

Then please download About:Buster from here:  http://www.malwarebytes.org/AboutBuster.zip .  Unzip it to the desktop, run it, Check for Updates, and click on *Update*.  If any updates are found, download and install them.  Then press the *Remove* button to run the tool.

When you reply, please include a fresh HijackThis log from your renamed .exe file and let me know if you are still having problems.

Thanks.  :rose:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Sun Java Installation/Update Instructions

The following procedure is strongly encouraged to remove older version Java components:
  •    Close any open programs you may have running, especially your web browser
  •    Click Start > Control Panel (Depending on your OS or configuration, you may have to click Start > Settings > Control Panel)
  •    Open Add or Remove Programs (If you have Windows 98 or Windows 2000, open Add/Remove Programs)
  •    Click once on any item listing J2SE or Java Runtime Environment in the name.  (Not every version of Java will begin with "Java" so be sure to read each entry in the list)

  •    Click the Remove or Change/Remove button
  •    Follow steps 4 and 5 as many times as necessary to remove all versions of Java
  •    Search 'Programs' and 'Application Data' and remove old version files manually.
    • C:\Program Files\
    • C:\Documents and Settings\USERNAME\Application Data\
    Quote
    Java Runtime Environment (JRE) 5.0 Update 8
    The J2SE Runtime Environment (JRE) allows end-users to run Java applications.   
    Installation Instructions | ReadMe  | ReleaseNotes | Sun License | Third Party Licenses

    •   Accept the agreement at the page that opens:
    Quote
    Required: You must accept the license agreement to download the product.
    • Click:  Accept License Agreement   
    • The page will refresh to Windows Platform - J2SE(TM) Runtime Environment 5.0 Update 8
    • It is recommended that you select:
    Quote
    Windows Offline Installation, Multi-language    jre-1_5_0_08-windows-i586-p.exe    15.74 MB
    •   After installing the downloaded file, restart your system again to finalize the process.
    ,  

    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

    Offline cyanide rose

    • Newbie
    • *
    • Posts: 13
    Re: cyanide rose's HijackThis log
    « Reply #4 on: September 19, 2006, 06:00:17 AM »
    Hi Corrine, I uninstalled the Java stuff but can't d/l the update as it's 15mb and I get cut off by the trojan dialer about 30 mins after coming online. I installed and used the other two programs but they didn't find anything.

    Here is my new 'OzHJT' log. ;)
    Logfile of HijackThis v1.99.1
    Scan saved at 2:34:21 PM, on 9/19/2006
    Platform: Windows XP  (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\Program Files\QuickTime\qttask.exe
    E:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Hijackthis\OzHJT.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com.au/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.29.0.1
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: (no name) - {516BD8CB-A5E0-475D-95A4-D7D665247CF2} - C:\WINDOWS\System32\pmkjh.dll
    O2 - BHO: (no name) - {8596FC60-68DE-132E-F1A8-671335AE69E3} - C:\WINDOWS\System32\fuoqvhv.dll (file missing)
    O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\System32\ixt1.dll (file missing)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\realplay.exe" /RunUPGToolCommandReBoot
    O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM95\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O20 - Winlogon Notify: pmkjh - C:\WINDOWS\System32\pmkjh.dll
    O20 - Winlogon Notify: wincqt32 - C:\WINDOWS\SYSTEM32\wincqt32.dll
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe

    Thanks again for helping me out with this, I really appreciate it. :)

    Offline SpyDie

    • The Spyware Cooker
    • Administrator
    • Hero Member
    • *****
    • Posts: 2045
      • The LandzDown Forum
    Re: cyanide rose's HijackThis log
    « Reply #5 on: September 23, 2006, 11:57:19 AM »
    Hiya,

    Just incase your topic slipped past, I thought I'd reply....

    Could you please try this?

    Please download VundoFix.exe to your desktop.
    • Double-click VundoFix.exe to run it.
    • Click the Scan for Vundo button.
    • Once it's done scanning, click the Remove Vundo button.
    • You will receive a prompt asking if you want to remove the files, click YES
    • Once you click yes, your desktop will go blank as it starts removing Vundo.
    • When completed, it will prompt that it will reboot your computer, click OK.
    • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
    Note: It is possible that VundoFix encountered a file it could not remove.
    In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
    Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'

    Offline Corrine

    • The Mystical Rose
    • Administrator
    • Hero Member
    • *****
    • Posts: 11530
    • "Stronger than the past, united in our goal."
      • Security Garden
    Re: cyanide rose's HijackThis log
    « Reply #6 on: September 23, 2006, 06:53:29 PM »
    Thanks, SpyDie.  The vacationing "MrCharlie" has returned so that should free up more of my time.

    Hi, cyanide rose.  I am sorry I missed your post.  Renaming the HJT.exe popped out just what we wanted to see.  Please follow SpyDie's instructions and one of us will get back to you after you post the logfiles.
    ,  

    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.

    Offline cyanide rose

    • Newbie
    • *
    • Posts: 13
    Re: cyanide rose's HijackThis log
    « Reply #7 on: October 02, 2006, 03:17:09 PM »
    Hi SpyDie and Corrine, I'm sorry I haven't gotten back to you guys earlier.

    My VundoFix log:

    VundoFix V6.1.6

    Checking Java version...

    Java version is 1.5.0.8

    Scan started at 1:09:32 AM 10/3/2006

    Listing files found while scanning....

    C:\WINDOWS\system32\emactfaq.dll
    C:\WINDOWS\system32\pmkjh.dll
    C:\WINDOWS\system32\hjkmp.ini
    C:\WINDOWS\system32\hjkmp.bak1
    C:\WINDOWS\system32\hjkmp.bak2
    C:\WINDOWS\system32\hjkmp.ini2
    C:\WINDOWS\system32\hjkmp.tmp
    C:\WINDOWS\system32\vlkujvep.dll
    C:\Program Files\Common Files\{381482F7-0790-1033-0922-030310070001}\services.dll

    Beginning removal...

     Attempting to delete C:\WINDOWS\system32\emactfaq.dll
    C:\WINDOWS\system32\emactfaq.dll Has been deleted!

     Attempting to delete C:\WINDOWS\system32\pmkjh.dll
    C:\WINDOWS\system32\pmkjh.dll Could not be deleted.

     Attempting to delete C:\WINDOWS\system32\hjkmp.ini
    C:\WINDOWS\system32\hjkmp.ini Has been deleted!

     Attempting to delete C:\WINDOWS\system32\hjkmp.bak1
    C:\WINDOWS\system32\hjkmp.bak1 Has been deleted!

     Attempting to delete C:\WINDOWS\system32\hjkmp.bak2
    C:\WINDOWS\system32\hjkmp.bak2 Has been deleted!

     Attempting to delete C:\WINDOWS\system32\hjkmp.ini2
    C:\WINDOWS\system32\hjkmp.ini2 Has been deleted!

     Attempting to delete C:\WINDOWS\system32\hjkmp.tmp
    C:\WINDOWS\system32\hjkmp.tmp Has been deleted!

     Attempting to delete C:\WINDOWS\system32\vlkujvep.dll
    C:\WINDOWS\system32\vlkujvep.dll Has been deleted!

     Attempting to delete C:\Program Files\Common Files\{381482F7-0790-1033-0922-030310070001}\services.dll
    C:\Program Files\Common Files\{381482F7-0790-1033-0922-030310070001}\services.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    VundoFix V6.1.6

    Checking Java version...

    Java version is 1.5.0.8

    Scan started at 1:12:55 AM 10/3/2006

    Listing files found while scanning....

    C:\WINDOWS\system32\pmkjh.dll

    Beginning removal...

     Attempting to delete C:\WINDOWS\system32\pmkjh.dll
    C:\WINDOWS\system32\pmkjh.dll Has been deleted!

    Performing Repairs to the registry.
    Done!


    New HijackThis log:
    Logfile of HijackThis v1.99.1
    Scan saved at 1:17:05 AM, on 10/3/2006
    Platform: Windows XP  (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\Program Files\iPod\bin\iPodService.exe
    E:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Hijackthis\OzHJT.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com.au/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O2 - BHO: (no name) - {B7672BAF-E9A3-49B6-86B2-C81719A18A4C} - C:\WINDOWS\System32\vlkujvep.dll (file missing)
    O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
    O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\realplay.exe" /RunUPGToolCommandReBoot
    O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM95\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe


    Offline cyanide rose

    • Newbie
    • *
    • Posts: 13
    Re: cyanide rose's HijackThis log
    « Reply #8 on: October 02, 2006, 05:35:56 PM »
    Sorry, further to this I've not able to access certain webpages since last night - I keep getting cannot find server messages for a couple of sites (on the same domain) that I know for a fact are up. This was prior to using VundoFix and is still happening after. I'm not sure if it's related or not, but it's bugging me like crazy anyway. :(

    Offline cyanide rose

    • Newbie
    • *
    • Posts: 13
    Re: cyanide rose's HijackThis log
    « Reply #9 on: October 02, 2006, 05:50:47 PM »
    Sorry, further to this I've not able to access certain webpages since last night - I keep getting cannot find server messages for a couple of sites (on the same domain) that I know for a fact are up. This was prior to using VundoFix and is still happening after. I'm not sure if it's related or not, but it's bugging me like crazy anyway. :(

    Please disregard this, I ran Spybot Search & Destroy and it found two nasties that were causing this error. :)

    Offline SpyDie

    • The Spyware Cooker
    • Administrator
    • Hero Member
    • *****
    • Posts: 2045
      • The LandzDown Forum
    Re: cyanide rose's HijackThis log
    « Reply #10 on: October 02, 2006, 08:26:30 PM »
    Atleast that problem got fixed. I'm sure you know how to 'fix' things using HijackThis. Just check the boxes beside each entry I list (the boxes inside HijackThis's scan results window, so you'll need to rescan with it), close all windows except Hijackthis and click 'Fix Checked'.

    O2 - BHO: (no name) - {B7672BAF-E9A3-49B6-86B2-C81719A18A4C} - C:\WINDOWS\System32\vlkujvep.dll (file missing)
    O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll


    Restart the computer, and then please delete this folder:

    C:\Program Files\VSToolbar\ (it's the 'VSToolbar' folder you'll want to delete)

    Also please tell us how things are now?
    Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'

    Offline cyanide rose

    • Newbie
    • *
    • Posts: 13
    Re: cyanide rose's HijackThis log
    « Reply #11 on: October 03, 2006, 06:54:15 AM »
    Ok I ran HijackThis again and fixed

    O2 - BHO: (no name) - {B7672BAF-E9A3-49B6-86B2-C81719A18A4C} - C:\WINDOWS\System32\vlkujvep.dll (file missing).

    But I couldn't find the following on the scan.

    O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll

    I think it's because that was what Spybot found and it deleted it. Everything seems to running great right now, and much faster too. Thanks so much to both you and Corrine for your assistance in getting rid of my problems! :D

    Offline SpyDie

    • The Spyware Cooker
    • Administrator
    • Hero Member
    • *****
    • Posts: 2045
      • The LandzDown Forum
    Re: cyanide rose's HijackThis log
    « Reply #12 on: October 03, 2006, 08:36:13 PM »
    OK, that's great :) Glad to help any time.

    You may wish to take a look at this topic for instructions on how to help prevent this happening again:

    http://www.landzdown.com/index.php?topic=2783.0
    Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'

    Offline cyanide rose

    • Newbie
    • *
    • Posts: 13
    Re: cyanide rose's HijackThis log
    « Reply #13 on: October 22, 2006, 08:23:14 AM »
    Hey guys, I have yet another problem that I hope you can help me out out with - I think I've been infected by W32/Vanebot-C. Here's my HijackThis log:

    Logfile of HijackThis v1.99.1
    Scan saved at 6:12:40 PM, on 10/22/2006
    Platform: Windows XP  (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\bootini.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\system32\slserv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
    E:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\slrundll.exe
    C:\Program Files\Hijackthis\OzHJT.exe

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://aapt.net.au
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    F2 - REG:system.ini: Shell=Explorer.exe bootini.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,bootini.exe
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [iTunesHelper] E:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
    O4 - HKLM\..\Run: [Microsoft Windows] bootini.exe
    O4 - HKCU\..\Run: [RealPlayer] "E:\Program Files\realplay.exe" /RunUPGToolCommandReBoot
    O4 - HKCU\..\Run: [Microsoft Windows] bootini.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O8 - Extra context menu item: Download with GetRight - E:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Open with GetRight Browser - E:\Program Files\GetRight\GRbrowse.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - E:\Program Files\Yahoo!\Messenger\yhexbmes0411.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM95\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O17 - HKLM\System\CCS\Services\Tcpip\..\{35367287-C957-459E-B71D-EAAFEB38169B}: NameServer = 203.12.160.35 203.12.160.36
    O17 - HKLM\System\CS1\Services\Tcpip\..\{35367287-C957-459E-B71D-EAAFEB38169B}: NameServer = 203.12.160.35 203.12.160.36
    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe


    Thanks in advance. :)

    Offline SpyDie

    • The Spyware Cooker
    • Administrator
    • Hero Member
    • *****
    • Posts: 2045
      • The LandzDown Forum
    Re: cyanide rose's HijackThis log
    « Reply #14 on: October 23, 2006, 06:10:20 PM »
    Hiya,

    You'll need to 'fix' these entries:

    F2 - REG:system.ini: Shell=Explorer.exe bootini.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe,bootini.exe
    O4 - HKLM\..\Run: [Microsoft Windows] bootini.exe
    O4 - HKCU\..\Run: [Microsoft Windows] bootini.exe


    I'm sure you know how to by now, so go ahead and 'fix' those entries & restart the computer. Post a new HijackThis logfile.

    I would also run an online antivirus scan:

    TrendMicro™ HouseCall Java Scan
    • Please go HERE to run the Trend Micro™ HouseCall Scan.
    • Click Scan now. It's free!
    • Read and put a Check next to Yes I accept the terms of use.
    • Click the Launching HouseCall>> button.
    • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
    • You may receive a Security Warning about the TrendMicro Java applet, click YES.
    • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
    • Please be patient while it installs, updates, and scans your system.
    • Once the scan is complete, it will take you to the summary page.
    • Under Cleanup options, choose clean all detected infections automatically.
    • Click the Clean now>> button.
    • If anything was found you may be prompted to run the scan again, you can just close the browser window.
    Beta. Software undergoes beta testing shortly before it's released. Beta is Latin for 'still doesn't work.'