This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Possible virus?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, this is a HJT log file of my fiancee's computer. When my computer was infected by a virus that I got from an MSN message, it sent an MSN message to this computer as well and my fiancee saved the file. So just in case there is something, below is the log file.

Once again thanks in advance guys.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:12:38 p.m., on 8/09/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAP\DAP.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\hpq\Shared\HPQTOA~1.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Eset\nod32.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\DOCUME~1\CASSAN~1\LOCALS~1\Temp\AVGDownloadManager\packages\35\setup.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
O4 - HKCU\..\Run: [anhtaas] C:\WINDOWS\system32\cvsdfw.exe
O4 - HKCU\..\Run: [Advanced SystemCare 3] "C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe" /startup
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: DVD Check.lnk = C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP\dapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe

–
End of file - 7659 bytes
Due, in part, to the large numbers of HJT logs being posted, there are four things that you need to be aware of.

1) If you have already posted this log at another forum, you need to post here that you have done so and this topic will be closed.
Multiple posting not only ties up valuable resources, but could also result is some unpleasant side-effects for your system if you follow two sets of instructions at the same time.
If, during research, an identical log is identified at another forum, this thread will be closed.

2) If you don't post a meaningful reply to any of my posts within five days, this thread will be closed. Due to limited free time I can only have so many open threads at any one time and if yours isn't active, somebody else's will be.
If, by omission, the thread hasn't be closed after five days and you post, it will just serve as a reminder to me to close it.
Please note that "I just dropped in to say Hi!" isn't a meaningful reply!

3) Malware removal is a tricky business, and malware writers don't tend to worry about the damage their creations do, so it is advisable to back-up all important files BEFORE we start. Although most cases have a successful conclusion, on occasion things don't go according to plan and it is better to be prepared for the worst.

4) Back-ups can get lost or damaged, so make two if the files are that important to you!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Sec-Info2.zip from here and save it to your Desktop. You will need to extract the file.

Right click on the zipped folder and from the menu that appears, click on Extract All…
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


You should now see a folder with a file in it - double click Sec-info2.vbs to run it.
Once you have been informed that the script has completed, a text file called Sec-Info.txt should be created in the same folder - you may need to wait a couple of seconds for it to appear..
Please copy and paste the contents of the text file into your next reply and then you can delete both of the folders and their contents.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download RootRepeal from one of the locations below and save it to your Desktop:
Location 1
Location 2
Location 3
  • Double click RootRepeal.exe to fire up the tool and OK any Windows confirmation if necessary.
  • Ensure that the Report Tab is selected at the bottom.
  • Click the Scan button, check ALL the boxes in the window that appears and then click OK.
  • Check the box next to your main hard drive - usually C: and click OK
  • Put the kettle on and perhaps open a packet of biscuits - the scan will take some time.
  • Once the scan has completed a Notepad window will open with the results in.
  • These results will also be saved to the root of your main drive as \RootRepeal report date time.txt
Let me have a copy of the contents in your next reply.
Hey there mate, really appreciate your time and help. here are the reports you asked for. ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/11 23:07 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xEF4D9000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: c:\documents and settings\cassandra\application data\limewire\mozilla-profile\places.sqlite-stmtjrnl Status: Allocation size mismatch (API: 16384, Raw: 0) Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\E9RU9LB1\q672681454_2650[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\E9RU9LB1\q712561684_1579[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q1198207302_5322[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q218101270_8667[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q508267720_1927[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q530147058_1435[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q557350938_3933[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q596880211_4492[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\q730591147_6207[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\s508267720_1927[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\s524584815_946[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\G9LB3V6W\s730591147_6207[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\errorPageStrings[1] Status: Locked to the Windows API! Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\q503565639_3864[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\q540970133_304[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\q705742656_184[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\q729987066_9164[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\s540970133_304[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\IT38AV64\s705742656_184[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\OULJWFV5\s1817932166_9760[1].jpg Status: Locked to the Windows API! Path: c:\documents and settings\cassandra\local settings\temporary internet files\content.ie5\ouljwfv5\nz-fnzgr6[2].htm Status: Allocation size mismatch (API: 8192, Raw: 288) Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\OULJWFV5\q1015862129_6402[1].jpg Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\Cassandra\Local Settings\Temporary Internet Files\Content.IE5\TCM3OEH2\q684905575_4519[1].jpg Status: Visible to the Windows API, but not on disk. ==EOF== Script run: 11/09/2009 11:02:24 p.m. ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: AVG Technologies AV Name: AVG Anti-Virus Free Version Number: 8.5 On-Access Scanning Enabled: Yes Product up-to-date: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ Company Name: ESET, spol. s r.o. AV Name: ESET NOD32 antivirus system 2.70 Version Number: 2.70 On-Access Scanning Enabled: Yes Product up-to-date: Yes ~~~~~~~~~~~~~~~~~~~~~~~~ The Windows Firewall is disabled. ~~~~~~~~~~~~~~~~~~~~~~~~ The Security Center Firewall Alerts are enabled. ~~~~~~~~~~~~~~~~~~~~~~~~ Number of Restore Points found: 30 ~~~~~~~~~~~~~~~~~~~~~~~~ Acrobat.com Adobe AIR Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1 Advanced SystemCare 3 Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver AVG Free 8.5 Bonjour Broadcom 802.11 Wireless LAN Adapter Comic Life Conexant AC-Link Audio Data Fax SoftModem with SmartCP Download Accelerator Plus (DAP) Driver Genius Professional Edition getPlus® for Adobe HijackThis 2.0.2 Hotfix for Windows XP (KB915865) HP Wireless Assistant 2.00 C1 InterVideo DVD Check InterVideo WinDVD iTunes Java™ 6 Update 11 LimeWire 5.2.13 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Visual C++ 2005 Redistributable NetWaiting NOD32 antivirus system QuickTime Synaptics Pointing Device Driver Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) Windows Internet Explorer 7 Windows Live Messenger
The first thing to deal with is your two anti-virus programs. Due to the potential for conflictions it is recommended to only run one AV in real-time, so you will need to decide whether you want AVG or NOD32 and uninstall the other. Once you've done that, do this:

Download Malwarebytes' Anti-Malware from here and save it to your Desktop - unless you already have it, in which case skip to the "updating" bit below.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Ensure a checkmark is placed next to both Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware and then click Finish.
  • If an update is found, it will download and install the latest version - you'll need to clear it with your firewall.
  • Once the program has loaded, select Perform full scan and then Scan.
  • When the scan has finished, click OK and then Show Results to view the results - no surprise there!
  • If MBAM finds anything, check the box(es) and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt
Let me have the MBAM log, a fresh HJT log (run in Normal Mode) AND a description of how your PC is behaving.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI