I believe that my computer is heavily infected with viruses, spyware, botware, etc. I've run the usual software, SPYBOT, Adaware, etc., and even de-fragged the disk. This has helped somewhat (although not much) but I need more for this computer to be functional.
Please help…I am posting the log file for hijackthis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:20:37 PM, on 10/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16915)
Boot mode: Normal
My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for the issues on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
Open [external image: Posted Image] on your desktop.
Click the [external image: Posted Image] tab.
Click the [external image: Posted Image] button.
In the Select Scan dialog, check [external image: Posted Image]
Push Ok
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
Copy/paste the log (that you've previously saved to your desktop) from RootRepeal onto your post.
Copy/paste the DDS.txt log (that you've previously saved to your desktop) onto your post.
Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Your Java is out of date.Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
Scroll down to where it says "JRE 6 Update 16".
Click the "Download" button to the right.
Select your Platform: "Windows".
Select your Language: "Multi-language".
Read the License Agreement, and then check the box that says: "Accept License Agreement".
Click Continue and the page will refresh.
Click on the link to download Windows Offline Installation and save the file to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u16-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:
Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
Under Temporary Internet Files, click the Settings… button
click the Delete Files button.
There are two options in the window to clear the cache - Leave both Checked
Applications and Applets
Trace and Log Files
Click OK on Delete Temporary Files Window Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
Click OK to leave the Temporary Files Settings
Click OK to leave the Java Control Panel.
ESET Online Scanner:
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install. All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
When prompted allow the Add-On/Active X to install.
Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology
Now click on: [external image: Posted Image]
The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
When completed the Online Scan will begin automatically.
Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
Now click on: [external image: Posted Image]
Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
ESETSmartInstaller@High as downloader log:
Can not open internetESETSmartInstaller@High as downloader log:
Can not open internetesets_scanner_update returned -1 esets_gle=1
esets_scanner_update returned -1 esets_gle=53251
esets_scanner_update returned -1 esets_gle=53251
# version=6
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6050
# api_version=3.0.2
# EOSSerial=d7e9b34bcf4a5041af12ca2a62b4b165
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2009-11-05 12:42:43
# local_time=2009-11-04 07:42:43 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=4865 21 100 100 526268750000
# scanned=430584
# found=39
# cleaned=0
# scan_time=40482
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-1ab034e7-62bca319.zip probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-2afc8601-6446b751.zip probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-4941f397-11ad9bc9.zip probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-4281f402.zip probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-65bdc427.zip probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Download\Portable_Time_Stopper_1.2.rar a variant of Win32/PSW.Delf.NRC trojan 00000000000000000000000000000000 I
C:\Download\Magical Key Finder\keyfinder.exe Win32/PSWTool.RAS.A application 00000000000000000000000000000000 I
C:\Download\Magical Key Finder\Magical Key Finder.zip Win32/PSWTool.RAS.A application 00000000000000000000000000000000 I
C:\Old Disk 1\Download\AddictionPinball-dm.exe a variant of Win32/Adware.Trymedia application 00000000000000000000000000000000 I
C:\Old Disk 1\Download\BSINSTALL.exe multiple threats 00000000000000000000000000000000 I
C:\Old Disk 1\Download\BSINSTALL2.exe multiple threats 00000000000000000000000000000000 I
C:\Old Disk 1\Download\BSINSTALL3.exe multiple threats 00000000000000000000000000000000 I
C:\Old Disk 1\Download\flight_simulator_2002_crack.exe a variant of Win32/Dialer.StarDialer application 00000000000000000000000000000000 I
C:\Old Disk 1\Download\Install_AIM.exe Win32/Adware.WBug.A application 00000000000000000000000000000000 I
C:\Old Disk 1\Download\kaaza.exe a variant of Win32/Dialer.StarDialer application 00000000000000000000000000000000 I
C:\Old Disk 1\Download\kazaa_lite_202_english.exe Win32/Adware.Altnet application 00000000000000000000000000000000 I
C:\Old Disk 1\Download\The_Sims-Livin_Large.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Old Disk 1\Download\Risk\CLASS.EXE probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Old Disk 1\Download\Risk\Risk 2+Crack.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
C:\Old Disk 1\Old Download\Install_AIM.exe Win32/Adware.WBug.A application 00000000000000000000000000000000 I
C:\Program Files\Morpheus\morpheustoolbar.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
C:\RECYCLER\S-1-5-21-1908096726-2267460080-512852799-1006\Dc21.zip Win32/Obfuscated.A1 trojan 00000000000000000000000000000000 I
C:\RECYCLER\S-1-5-21-1908096726-2267460080-512852799-1006\Dc22.zip Win32/Obfuscated.A1 trojan 00000000000000000000000000000000 I
C:\RECYCLER\S-1-5-21-1908096726-2267460080-512852799-1006\Dc23.exe Win32/Obfuscated.A1 trojan 00000000000000000000000000000000 I
J:\Download\AddictionPinball-dm.exe a variant of Win32/Adware.Trymedia application 00000000000000000000000000000000 I
J:\Download\BSINSTALL.exe multiple threats 00000000000000000000000000000000 I
J:\Download\BSINSTALL2.exe multiple threats 00000000000000000000000000000000 I
J:\Download\Install_AIM.exe Win32/Adware.WBug.A application 00000000000000000000000000000000 I
J:\Download\Risk\CLASS.EXE probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
J:\Download\Risk\Risk 2+Crack.exe probably a variant of Win32/Agent trojan 00000000000000000000000000000000 I
J:\Program Files\aim\Sysfiles\WxBug.EXE Win32/Adware.WBug.A application 00000000000000000000000000000000 I
J:\Program Files\Common Files\csshare\plugins\npclntax.dll Win32/Adware.180Solutions application 00000000000000000000000000000000 I
J:\Program Files\Common Files\csshare\plugins0942\npclntax.dll Win32/Adware.180Solutions application 00000000000000000000000000000000 I
J:\Program Files\Mozilla Firefox\plugins\npclntax.dll Win32/Adware.180Solutions application 00000000000000000000000000000000 I
J:\WINDOWS\system\abc.exe Win32/RemoteAdmin application 00000000000000000000000000000000 I
J:\WINDOWS\system\fullname.txt IRC/Cloner.AV trojan 00000000000000000000000000000000 I
J:\WINDOWS\system\ident.txt IRC/Cloner.AV trojan 00000000000000000000000000000000 I
J:\WINDOWS\system\nicks.txt IRC/Cloner.AV trojan 00000000000000000000000000000000 I
J:\WINDOWS\system32\r_server.exe Win32/RemoteAdmin application 00000000000000000000000000000000 I
Well, that appears to have revealed the crux of your problem. You download pirated and contaminated software.
Please download the OTM by OldTimer.
Save it to your desktop.
Please double-click OTM.exe to run it.
(Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
:Processes
:Files
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-1ab034e7-62bca319.zip
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-2afc8601-6446b751.zip
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-4941f397-11ad9bc9.zip
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6b13a7e7-4281f402.zip
C:\Documents and Settings\Owner.FAMILY\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-b825669-65bdc427.zip
C:\Download\Portable_Time_Stopper_1.2.rar
C:\Download\Magical Key Finder\keyfinder.exe
C:\Download\Magical Key Finder\Magical Key Finder.zip
C:\Old Disk 1\Download\AddictionPinball-dm.exe
C:\Old Disk 1\Download\BSINSTALL.exe
C:\Old Disk 1\Download\BSINSTALL2.exe
C:\Old Disk 1\Download\BSINSTALL3.exe
C:\Old Disk 1\Download\flight_simulator_2002_crack.exe
C:\Old Disk 1\Download\Install_AIM.exe
C:\Old Disk 1\Download\kaaza.exe
C:\Old Disk 1\Download\kazaa_lite_202_english.exe
C:\Old Disk 1\Download\The_Sims-Livin_Large.exe
C:\Old Disk 1\Download\Risk\CLASS.EXE
C:\Old Disk 1\Download\Risk\Risk 2+Crack.exe
C:\Old Disk 1\Old Download\Install_AIM.exe
C:\Program Files\Morpheus\morpheustoolbar.exe
C:\RECYCLER\S-1-5-21-1908096726-2267460080-512852799-1006\Dc21.zip
C:\RECYCLER\S-1-5-21-1908096726-2267460080-512852799-1006\Dc22.zip
C:\RECYCLER\S-1-5-21-1908096726-2267460080-512852799-1006\Dc23.exe
J:\Download\AddictionPinball-dm.exe
J:\Download\BSINSTALL.exe
J:\Download\BSINSTALL2.exe
J:\Download\Install_AIM.exe
J:\Download\Risk\CLASS.EXE
J:\Download\Risk\Risk 2+Crack.exe
J:\Program Files\aim\Sysfiles\WxBug.EXE
J:\Program Files\Common Files\csshare\plugins\npclntax.dll
J:\Program Files\Common Files\csshare\plugins0942\npclntax.dll
J:\Program Files\Mozilla Firefox\plugins\npclntax.dll
J:\WINDOWS\system\abc.exe
J:\WINDOWS\system\fullname.txt
J:\WINDOWS\system\ident.txt
J:\WINDOWS\system\nicks.txt
J:\WINDOWS\system32\r_server.exe
:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)