This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Possible trojan and browser hijacker.

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't even get Windows to start normally, it loads too slow. I can start it in safe mode, which is the only way i can run a hijackthis log.

I'm not sure what information you need, so i'll answer any questions in your reply.








Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:50:01 AM, on 2/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\TEMP\C6CA.tmp
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Flock\flock\flock.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: 195.245.119.131 browser-security.microsoft.com
O2 - BHO: C:\WINDOWS\system32\hsfd83jfdg.dll - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hsfd83jfdg.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [lsass driver] C:\WINDOWS\msauc.exe
O4 - HKLM\..\Run: [Vzeyogoyineba] rundll32.exe "C:\WINDOWS\Mwinubasebiw.dll",e
O4 - HKLM\..\Run: [lrijh8s73jhbfgfd] C:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [\\Owner-pc\EPSON Stylus CX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE /FU "C:\DOCUME~1\Owner\LOCALS~1\Temp\E_S3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [sysguard] C:\WINDOWS\sysguard.exe
O4 - HKCU\..\Run: [svschost.exe] C:\WINDOWS\system32\svschost.exe -check
O4 - HKCU\..\Run: [lrijh8s73jhbfgfd] C:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe
O4 - HKCU\..\Run: [44138497242337706662347701380875] C:\Program Files\Antivirus 2009\av2009.exe
O4 - HKCU\..\Run: [MS AntiSpyware 2009] "C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: XtremeFiles.lnk = C:\Program Files\Xtreme\XtremeFiles.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{904ADB30-B1FE-4BF1-AE7A-99FFB66A205F}: NameServer = 192.168.2.1
O20 - Winlogon Notify: crypt - C:\WINDOWS\SYSTEM32\crypts.dll
O22 - SharedTaskScheduler: Windowz Updater - {259BA022-2005-45E9-A965-10EDB9C00618} - (no file)
O22 - SharedTaskScheduler: g322 - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00322} - (no file)
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O22 - SharedTaskScheduler: erajhsf8743kjrngjnf - {D5BF4552-94F1-42BD-F434-3604812C807D} - C:\WINDOWS\system32\rah3b8ffdnd.dll
O22 - SharedTaskScheduler: jgzfkj9w38rksndfi7r4 - {C5BF49A2-94F3-42BD-F434-3604812C8955} - C:\WINDOWS\system32\hsfd83jfdg.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TiVo Install Helper (TivoInstallHelper) - TiVo Inc. - C:\DOCUME~1\Owner\LOCALS~1\Temp\MSI29.tmp
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 6894 bytes
Hi there you have several problems which I will try to disable/kill in one sweep. Please run the following analysis programme from safe mode

To ensure that I get all the information this log will need to be attached (instructions at the end) if it is to large to attach then upload to Mediafire and post the sharing link.

Download OTScanit2 to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanit folder and double-click on OTScanit.exe to start the program.
  • Check the box that says Scan All Users
  • Check the Radio button for Rootkit check YES
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
OK this is the first quick and dirty clean now that I can see what I am up against. You probably picked all of these up by using P2P applications I would strongly suggest that you stop using them

One or more of the identified infections is a backdoor Trojan and a key logger.

If this computer is ever used for on-line banking, I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a clean computer, change ALL your on-line passwords for email, for banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.


Start OTScanit. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Unregister Dlls]
[Processes - Safe List]
YY -> e1a5.tmp -> %SystemRoot%\temp\E1A5.tmp
YY -> svñshost.exe -> %SystemRoot%\system32\svñshost.exe
YY -> svschost.exe -> %SystemRoot%\system32\svschost.exe
[Driver Services - Safe List]
YY -> (raawhvmttmotd) raawhvmttmotd [Kernel | Auto | Stopped] -> %SystemRoot%\system32\drivers\ckfqha.sys
[Registry - Safe List]
< HOSTS File > (784 bytes and 21 lines) -> C:\WINDOWS\System32\drivers\etc\Hosts
YN -> 195.245.119.131 browser-security.microsoft.com -> 
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YY -> {C5BF49A2-94F3-42BD-F434-3604812C8955} [HKLM] -> %SystemRoot%\system32\hsfd83jfdg.dll [C:\WINDOWS\system32\hsfd83jfdg.dll]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer ToolBars [HKEY_USERS\S-1-5-21-3869047767-4027495630-107577635-1003\] > -> HKEY_USERS\S-1-5-21-3869047767-4027495630-107577635-1003\Software\Microsoft\Internet Explorer\Toolbar\
YN -> ShellBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
YN -> WebBrowser\\"{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Reg Error: Key does not exist or could not be opened.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "lrijh8s73jhbfgfd" -> %UserProfile%\Local Settings\Temp\winlognn.exe [C:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe]
YY -> "lsass driver" -> %SystemRoot%\msauc.exe [C:\WINDOWS\msauc.exe]
YN -> "RegistryMechanic" -> []
YY -> "Vzeyogoyineba" -> %SystemRoot%\Mwinubasebiw.dll [rundll32.exe "C:\WINDOWS\Mwinubasebiw.dll",e]
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "44138497242337706662347701380875" -> %ProgramFiles%\Antivirus 2009\av2009.exe [C:\Program Files\Antivirus 2009\av2009.exe]
YY -> "lrijh8s73jhbfgfd" -> %UserProfile%\Local Settings\Temp\winlognn.exe [C:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe]
YY -> "MS AntiSpyware 2009" -> %AllUsersProfile%\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe ["C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun]
YY -> "svschost.exe" -> %SystemRoot%\system32\svschost.exe [C:\WINDOWS\system32\svschost.exe -check]
YY -> "sysguard" -> %SystemRoot%\sysguard.exe [C:\WINDOWS\sysguard.exe]
YY -> "tezrtsjhfr84iusjfo84f" -> %UserProfile%\Local Settings\Temp\csrssc.exe [C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe]
< Run [HKEY_USERS\S-1-5-21-3869047767-4027495630-107577635-1003\] > -> HKEY_USERS\S-1-5-21-3869047767-4027495630-107577635-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "44138497242337706662347701380875" -> %ProgramFiles%\Antivirus 2009\av2009.exe [C:\Program Files\Antivirus 2009\av2009.exe]
YY -> "lrijh8s73jhbfgfd" -> %UserProfile%\Local Settings\Temp\winlognn.exe [C:\DOCUME~1\Owner\LOCALS~1\Temp\winlognn.exe]
YY -> "MS AntiSpyware 2009" -> %AllUsersProfile%\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe ["C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe" /autorun]
YY -> "svschost.exe" -> %SystemRoot%\system32\svschost.exe [C:\WINDOWS\system32\svschost.exe -check]
YY -> "sysguard" -> %SystemRoot%\sysguard.exe [C:\WINDOWS\sysguard.exe]
YY -> "tezrtsjhfr84iusjfo84f" -> %UserProfile%\Local Settings\Temp\csrssc.exe [C:\DOCUME~1\Owner\LOCALS~1\Temp\csrssc.exe]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"CLSID" [HKLM] -> [{0000031A-0000-0000-C000-000000000046}]
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"ClsidExtension" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"Default Visible" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
< Internet Explorer Extensions [HKEY_USERS\S-1-5-21-3869047767-4027495630-107577635-1003\] > -> HKEY_USERS\S-1-5-21-3869047767-4027495630-107577635-1003\Software\Microsoft\Internet Explorer\Extensions\
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"ButtonText" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"CLSID" [HKLM] -> [{0000031A-0000-0000-C000-000000000046}]
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"ClsidExtension" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
YN -> {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52}\\"Default Visible" [HKLM] -> [Reg Error: Key does not exist or could not be opened.]
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YY -> crypt -> %SystemRoot%\system32\crypts.dll
< SharedTaskScheduler [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler
YN -> "{259BA022-2005-45E9-A965-10EDB9C00618}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [Windowz Updater]
YN -> "{A4F94C0C-54A7-4DB1-9AF3-B22E63D00322}" [HKLM] -> Reg Error: Key does not exist or could not be opened. [g322]
YY -> "{C5BF49A2-94F3-42BD-F434-3604812C8955}" [HKLM] -> %SystemRoot%\system32\hsfd83jfdg.dll [jgzfkj9w38rksndfi7r4]
YY -> "{D5BF4552-94F1-42BD-F434-3604812C807D}" [HKLM] -> %SystemRoot%\system32\rah3b8ffdnd.dll [erajhsf8743kjrngjnf]
< IFEO [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
YY -> explorer.exe -> %ProgramFiles%\Microsoft Common\svchost.exe [Debugger]
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
*SecurityProviders* -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
YY ->  digeste.dll -> %SystemRoot%\system32\digeste.dll
< SecurityProviders [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders
[Files/Folders - Created Within 30 Days]
NY -> digeste.dll -> %SystemRoot%\System32\digeste.dll
NY -> iehelper.dll -> %SystemRoot%\System32\iehelper.dll
NY -> TDSSxxiu.sys -> %SystemRoot%\System32\drivers\TDSSxxiu.sys
NY -> TDSSkalo.dll -> %SystemRoot%\System32\TDSSkalo.dll
NY -> ieupdates.exe -> %SystemRoot%\System32\ieupdates.exe
NY -> scui.cpl -> %SystemRoot%\System32\scui.cpl
NY -> $$$$$$$$.bat -> %SystemRoot%\System32\$$$$$$$$.bat
NY -> hsfd83jfdg.dll -> %SystemRoot%\System32\hsfd83jfdg.dll
NY -> system32.exe -> %SystemRoot%\system32.exe
NY -> kernel32.exe -> %SystemRoot%\kernel32.exe
NY -> CrucialSoft Ltd -> %AllUsersProfile%\Application Data\CrucialSoft Ltd
NY -> rah3b8ffdnd.dll -> %SystemRoot%\System32\rah3b8ffdnd.dll
NY -> svschost.exe -> %SystemRoot%\System32\svschost.exe
NY -> svñshost.exe -> %SystemRoot%\System32\svñshost.exe
NY -> Mwinubasebiw.dll -> %SystemRoot%\Mwinubasebiw.dll
NY -> str.sys -> %SystemRoot%\System32\drivers\str.sys
NY -> msauc.exe -> %SystemRoot%\msauc.exe
NY -> crypts.dll -> %SystemRoot%\System32\crypts.dll
NY -> ckfqha.sys -> %SystemRoot%\System32\drivers\ckfqha.sys
NY -> shell31.dll -> %SystemRoot%\System32\shell31.dll
NY -> wpv881234083759.cpx -> %SystemRoot%\System32\wpv881234083759.cpx
NY -> wpv671234083698.cpx -> %SystemRoot%\System32\wpv671234083698.cpx
NY -> sysguard.exe -> %SystemRoot%\sysguard.exe
NY -> Microsoft Common -> %ProgramFiles%\Microsoft Common
NY -> Mandy Morbid - Tentacle Rape -> %UserProfile%\Desktop\Mandy Morbid - Tentacle Rape
NY -> 58b8791b527f165a21 -> %SystemDrive%\58b8791b527f165a21
NY -> mm.BOT -> %ProgramFiles%\mm.BOT
[Files/Folders - Modified Within 30 Days]
NY -> csrssc.exe -> %UserProfile%\Local Settings\Temp\csrssc.exe
NY -> l26[1].exe -> %UserProfile%\Local Settings\Temp\Temporary Internet Files\Content.IE5\N6YE4GVQ\l26[1].exe
NY -> 162[1].exe -> %UserProfile%\Local Settings\Temp\Temporary Internet Files\Content.IE5\N6YE4GVQ\162[1].exe
NY -> soft[1].exe -> %UserProfile%\Local Settings\Temp\Temporary Internet Files\Content.IE5\N6YE4GVQ\soft[1].exe
NY -> svschost.exe -> %SystemRoot%\System32\svschost.exe
NY -> svñshost.exe -> %SystemRoot%\System32\svñshost.exe
NY -> Mwinubasebiw.dll -> %SystemRoot%\Mwinubasebiw.dll
NY -> digeste.dll -> %SystemRoot%\System32\digeste.dll
NY -> iehelper.dll -> %SystemRoot%\System32\iehelper.dll
NY -> $$$$$$$$.bat -> %SystemRoot%\System32\$$$$$$$$.bat
NY -> TDSSxxiu.sys -> %SystemRoot%\System32\drivers\TDSSxxiu.sys
NY -> TDSSkalo.dll -> %SystemRoot%\System32\TDSSkalo.dll
NY -> system32.exe -> %SystemRoot%\system32.exe
NY -> kernel32.exe -> %SystemRoot%\kernel32.exe
NY -> ieupdates.exe -> %SystemRoot%\System32\ieupdates.exe
NY -> scui.cpl -> %SystemRoot%\System32\scui.cpl
NY -> hsfd83jfdg.dll -> %SystemRoot%\System32\hsfd83jfdg.dll
NY -> winlognn.exe -> %UserProfile%\Local Settings\Temp\winlognn.exe
NY -> rah3b8ffdnd.dll -> %SystemRoot%\System32\rah3b8ffdnd.dll
NY -> str.sys -> %SystemRoot%\System32\drivers\str.sys
NY -> crypts.dll -> %SystemRoot%\System32\crypts.dll
NY -> ckfqha.sys -> %SystemRoot%\System32\drivers\ckfqha.sys
NY -> shell31.dll -> %SystemRoot%\System32\shell31.dll
NY -> msauc.exe -> %SystemRoot%\msauc.exe
NY -> wJQs.exe -> %UserProfile%\Local Settings\Temp\wJQs.exe
NY -> sysguard.exe -> %SystemRoot%\sysguard.exe
NY -> xpdes.dll -> %UserProfile%\Local Settings\Temp\xpdes.dll
[Alternate Data Streams]
NY -> @Alternate Data Stream - 0 bytes -> %SystemRoot%\unvise32qt.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
NY -> @Alternate Data Stream - 114 bytes -> %AllUsersProfile%\Application Data\TEMP:B835CF2D
NY -> @Alternate Data Stream - 150 bytes -> %AllUsersProfile%\Application Data\TEMP:30FD0CBD
NY -> @Alternate Data Stream - 88 bytes -> %SystemRoot%\unvise32qt.exe:SummaryInformation
[File - Lop Check]
NY -> CrucialSoft Ltd -> C:\Documents and Settings\All Users\Application Data\CrucialSoft Ltd
[Empty Temp Folders]
[Start Explorer]
[Reboot]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new Hijackthis log.

I will review the information when it comes back in.

THEN

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
I tried running it, it said it couldn't find this file and then it crashed and i had to restart: NY -> shell31.dll -> %SystemRoot%\System32\shell31.dll
OK then new tack delete combofix

Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.

You may need to rename the report to drweb.txt to upload it
📎DrWeb.txt

Also, i started Windows normally and it seems to be running well except my background won't work no matter what i try. It just says the Active Desktop Recovery bs.

Here's a new hijackthis file if needed.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:04:26 PM, on 2/14/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Xtreme\XtremeFiles.exe
C:\Program Files\Flock\flock\flock.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ÿþ# Copyright © 1993-1999 Microsoft Corp.
O2 - BHO: (no name) - {5dacfe7a-8045-4e11-d4e4-6c0910336c1c} - C:\WINDOWS\uwotetabejuyokuy.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Twoseguwivi] rundll32.exe "C:\WINDOWS\uwotetabejuyokuy.dll",e
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [\\Owner-pc\EPSON Stylus CX4400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAA.EXE /FU "C:\DOCUME~1\Owner\LOCALS~1\Temp\E_S3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: XtremeFiles.lnk = C:\Program Files\Xtreme\XtremeFiles.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - (no file) (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O17 - HKLM\System\CCS\Services\Tcpip\..\{904ADB30-B1FE-4BF1-AE7A-99FFB66A205F}: NameServer = 192.168.2.1
O22 - SharedTaskScheduler: IE Component Categories cache daemon - {553858A7-4922-4e7e-B1C1-97140C1C16EF} - C:\WINDOWS\system32\ieframe.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TiVo Install Helper (TivoInstallHelper) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\MSI29.tmp (file missing)
O24 - Desktop Component 0: (no name) - (no file)

–
End of file - 5939 bytes
Progress :thumbup:

Everything now will be done in normal mode

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O1 - Hosts: ÿþ# Copyright © 1993-1999 Microsoft Corp.
O2 - BHO: (no name) - {5dacfe7a-8045-4e11-d4e4-6c0910336c1c} - C:\WINDOWS\uwotetabejuyokuy.dll
O4 - HKLM\..\Run: [Twoseguwivi] rundll32.exe "C:\WINDOWS\uwotetabejuyokuy.dll",e
O24 - Desktop Component 0: (no name) - (no file)

Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.

THEN

Fresh copy

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
OK different size hammer then. What is the current state of your computer ?

We will now do a deep search of your processes and files

Download avz4.zip from here
  • Unzip it to your desktop to a folder named avz4
  • Double click on AVZ.exe to run it.
  • Run an update by clicking the Auto Update button on the Right of the Log window: [external image: Posted Image]
  • Click Start to begin the update
Note: If you recieve an error message, chose a different source, then click Start again


  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the "Healing/Quarantine and Advanced System Investigation" check box.
  • Click on the “Execute selected scripts”.
  • Automatic scanning, healing and system check will be executed.
  • A logfile (avz_sysinfo.htm) will be created and saved in the LOG folder in the AVZ directory as virusinfo_syscure.zip.
  • It is necessary to reboot your machine, because AVZ might disturb some program operations (like antiviruses and firewall) during the system scan.
  • All applications will work properly after the system restart.

When restarted

  • Start AVZ.
  • Choose from the menu "File" => "Standard scripts " and mark the “Advanced System Investigation" check box.
  • Click on the "Execute selected scripts".
  • A system check will be automatically performed, and the created logfile (avz_sysinfo.htm) will be saved in the LOG folder in the AVZ directory as virusinfo_syscheck.zip.

Attach both zip files to your next post

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI