Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)
![]() ![]() |
Jan 3 2008, 09:41 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
What I got for Christmas was Internet Speed Monitor, Then Malware performing a system scan and more. Blasted IE6 with Popups and pop unders, asking me to install malware removal from clickspring.net and purity scan. Eventually overload browser and forced restart numerous times. Brought tower to I T friend he installed and ran another AV Program and Then windows would not start at all. Had to use restore point to get xp running again. Actions and infections: Antivirus Symantec Client Security 9.0 picked up some of it but left alot behind, Spybot S & D found some more and attempted to fix. MIcrosoft recommended automatic updates and new service pack included IE7 which shutdown my browser when attempting any dowloads. I attempted to use error report log to find problem and attempt fix. AV suggested it to be "Win32.Trats" virus infection has quarantined entries and then Symantec iself would start at startup attempting to be installed by Win Installer. Current State: I have rolled back IE 7 to IE 6. Have ability to download though New windows in IE still have problems, they open slow or not at all. But was finally able to dowload and install rogue removal kit, HJT Combofix, Rar, ....and other programs. Ran Combofix only and came here, since I was noticing alot of caveats about this program and HJT and others. This site was recommended and I had been reading some of the posts and HJT Logs to se if similar entires and problems to mine were posted by other users. I am pleased to finally make it here and I am posting the latest HJT next. Thank you in advance Have a Great day Denise Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:41:33 AM, on 04/01/08 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe c:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing) O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing) O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Documents and Settings\Owner\Start Menu\Programs\Poker.com\Poker.com.lnk (HKCU) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O15 - Trusted Zone: http://onecare.live.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/shared/m...83/mcinsctl.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1198644143593 O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aol.com/molbin/shared/m...,20/mcgdmgr.cab O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Compaq Local Alerter (CPQALERT) - Compaq Computer Corporation - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe O23 - Service: Compaq DMI Web Agent (cpqWebDmi) - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe -- End of file - 6801 bytes This post has been edited by denise manager: Jan 4 2008, 11:07 AM |
|
|
|
Jan 5 2008, 10:02 AM
Post
#2
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
http://forums.whatthetech.com/WARNING_t86364.html
WARNING !!! DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision. Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data. Combofix changes almost daily to keep up with new infections.
After the above. I suggest you do this: Double-click My Computer. Click the Tools menu, and then click Folder Options. Click the View tab. Clear "Hide file extensions for known file types." Under the "Hidden files" folder, select "Show hidden files and folders." Clear "Hide protected operating system files." Click Apply, and then click OK. Please do not delete anything unless instructed to. Next: Please download ATF Cleaner by Atribune. Download - ATF Cleaner» Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. (If you use FireFox or the Opera browser To keep saved passwords, click No at the prompt.) It's normal after running ATF cleaner that the PC will be slower to boot the first time. Next: Download ComboFix from Here to your Desktop. **Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop** --------------------------------------------------------------------
-------------------------------------------------------------------- Double click on combofix.exe & follow the prompts. When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze **** *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections. |
|
|
|
Jan 5 2008, 11:02 AM
Post
#3
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Hello LD
I appreciate the help. I attempted instructions as per your response. Combofix will not run it generates error " Combofix.exe has caused error shlwapi.dll" and wants to send report to microsoft. I am stuck for the moment I will await next response Regards Denise |
|
|
|
Jan 5 2008, 11:07 AM
Post
#4
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
|
|
|
|
Jan 5 2008, 11:14 AM
Post
#5
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Dear LD
Thank you for your help. I cannot access DR Web Cureit When I click link a blank window appears and times out, IE hangs If I right click link to save to desktop I receive error " connect with server was reset" Im kinda stuck again. Regards Denise |
|
|
|
Jan 5 2008, 11:21 AM
Post
#6
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall. * After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix. * Reconnect to the internet * Post the following logs/Reports:
|
|
|
|
Jan 5 2008, 11:30 AM
Post
#7
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Hello LD
I attempted instructions and pasted into run box - Combofix window comes up "paused" then generated error "shlwapi.dll" and closed combofix again. I am able to get forums here, but thats about it. Regards Denise |
|
|
|
Jan 5 2008, 11:41 AM
Post
#8
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
Run windows updates and get IE 7 again.
Then try combofix again |
|
|
|
Jan 5 2008, 12:57 PM
Post
#9
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Hello LD
Tried to run windows updates...No Luck missing files again. IE explorer will not open pages They just appear blank and stall I can really only get here and a few other places Regards Denise |
|
|
|
Jan 5 2008, 01:02 PM
Post
#10
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
You could try System Restore.
1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked. |
|
|
|
Jan 5 2008, 01:47 PM
Post
#11
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Hello LD
OK found restore point and now have IE7 and all windows updates installed. Took a bit but back here now, and all is ok so far. Regards Denise |
|
|
|
Jan 5 2008, 01:55 PM
Post
#12
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
I suggest you do this:
Double-click My Computer. Click the Tools menu, and then click Folder Options. Click the View tab. Clear "Hide file extensions for known file types." Under the "Hidden files" folder, select "Show hidden files and folders." Clear "Hide protected operating system files." Click Apply, and then click OK. Please do not delete anything unless instructed to. Next: Please download ATF Cleaner by Atribune. Download - ATF Cleaner» Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. (If you use FireFox or the Opera browser To keep saved passwords, click No at the prompt.) It's normal after running ATF cleaner that the PC will be slower to boot the first time. Next: Download ComboFix from Here to your Desktop. **Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop** --------------------------------------------------------------------
-------------------------------------------------------------------- Double click on combofix.exe & follow the prompts. When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review ****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze **** *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections. |
|
|
|
Jan 5 2008, 02:06 PM
Post
#13
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Hello LD
ATF dowloaded and worked fine. Dowloaded combofix and tried to start program.......Got same error as before Please Advise Thank you for your help Regards Denise |
|
|
|
Jan 5 2008, 02:09 PM
Post
#14
|
|
![]() Forum God Group: Root Admin Posts: 40,577 Joined: 23-September 04 From: Missouri, USA Member No.: 15,276 |
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
|
|
|
|
Jan 5 2008, 04:10 PM
Post
#15
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 50 Joined: 3-January 08 From: fairmont, wv Member No.: 75,667 Operating System: Windows xp sp2, ***working off old win 98 se laptop too |
Hello LDT:
Here is the log you requested from Drweb. setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131;Probably BACKDOOR.Trojan;Moved.; |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | ||
|---|---|---|---|---|---|---|
![]() |
16 | wooderson23 | 491 | 5 minutes ago Last post by: shelf life |
||
![]() |
6 | Boston | 33 | Today, 08:14 PM Last post by: Tomk |
||
![]() |
18 | MotownMark | 230 | Today, 07:32 PM Last post by: mschroe919 |
||
![]() |