This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HijackThis Logs

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

As of yeseterday, my computer started getting fake alerts and anti-virus's randomly and I have not able to get rid of the problem. I fear it is something more than just some fake alerts though.

Here are the HijackThis logs, although I'm not sure if they are accurate as I believe there is a virus corrupting it due to the screenshot provided below:

[external image: Posted Image]

And here are the logs:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:55:24 PM, on 4/14/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17023)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\System32\aniServ.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MSSConnectorService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Home Server\WHSConnector.exe
C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe
C:\WINDOWS\system32\ctfmon.exe
C:\program files\windows live\messenger\msnmsgr .exe
c:\program files\superantispyware\superantispyware .exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [Adobe_Reader] c:\program files\internet explorer\wmpscfgs.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr .exe" /background
O20 - AppInit_DLLs: app_dll.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Airgo Networks NIC Service (ANISERVICE) - Airgo Networks, Inc. - C:\WINDOWS\System32\aniServ.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - FirebirdSQL Project - C:\Program Files\Firebird\Firebird_2_1\bin\fbserver.exe
O23 - Service: HPMSSConnectorService (HPMSSConnectorSvc) - HP - C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MSSConnectorService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 3233 bytes
Hello Krunkdog and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
Krunkdog,

You have an infection that will take a few rounds to kill, so please be patient and stick with me.

🖼Click to load external image (Posted Image) Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    netsvcs
    %systemroot%\system32\drivers\*.sys /90
    %SYSTEMDRIVE%\*.exe
    /md5start
    msnmsgr*
    superantispyware*
    msnmsgr*
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please include the following in your next post:
  • OTL and Extras logs
  • GMER log
Krunkdog,

🖼Click to load external image (Posted Image) You are infected with a trojan know to sometimes have backdoor properties and a rootkit. Rootkits and Backdoor Trojans are very dangerous because they can steal sensitive information which they send back to the hacker. If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately limit your online activity until your system is cleaned. All passwords should be changed immediately using a different computer and banking and credit card institutions should be notified of the possible security breach.

These infections will take several steps to clean, and we may need your Windows XP installation disk. Do you have it, or can you borrow one? Here are your first instructions:

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - c:\Documents and Settings\Michael\Local Settings\temp\ctv143 .exe ()
    PRC - C:\Program Files\Internet Explorer\wmpscfgs.exe ()
    O4 - HKLM..\Run: [Adobe_Reader] c:\Program Files\Internet Explorer\wmpscfgs.exe ()
    O20 - AppInit_DLLs: (app_dll.dll) -  File not found
    [2010/04/14 14:42:56 | 000,014,710 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\50vGiJ1FW7x2
    [2010/04/14 12:57:52 | 000,014,762 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\50vGiJ1FW7x2
    [2010/04/13 18:51:59 | 000,181,248 | -HS- | M] () – C:\Documents and Settings\Michael\Local Settings\Application Data\3397709227.dll
    [2010/04/13 18:48:42 | 000,010,832 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\4T227ly4
    [2010/04/13 18:48:41 | 000,010,832 | -HS- | M] () – C:\Documents and Settings\Michael\Local Settings\Application Data\4T227ly4
    [2010/04/13 17:07:49 | 000,010,804 | -HS- | M] () – C:\Documents and Settings\Michael\Local Settings\Application Data\1040348557
    [2010/04/13 17:07:49 | 000,010,804 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\1040348557
    [2010/04/13 16:48:47 | 000,001,175 | —- | M] () – C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll
    [2006/12/13 18:52:36 | 000,086,016 | —- | C] () – C:\WINDOWS\CMedia.dll
    [2010/04/13 17:37:54 | 000,031,232 | —- | M] () MD5=EAEB0492C36B1E900F5E713191584721 – C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    [2010/04/15 14:06:45 | 000,031,232 | —- | M] () MD5=EAEB0492C36B1E900F5E713191584721 – C:\Program Files\SUPERAntiSpyware\superantispyware.exe
    
    :Files
    c:\Documents and Settings\Michael\Local Settings\temp\ctv143 .exe
    C:\WINDOWS\Tasks\At*.job
    
    :Commands
    [purity]
    [EMPTYTEMP]
    [EMPTYFLASH]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Double click on OTL to open it
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Under the Custom Scan box paste this in:
    /md5start
    dmio.sys
    /md5stop

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open a notepad window. OTL.Txt. This is saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) and paste the contents of that file into your next post.
Please include the following in your next post:
  • OTL fix log
  • New OTL scan log
I'm pretty sure I have the Windows XP Installation disk I'll have to go look for it. I've attached the OTL scan log, although I can not find where the fix log saved to.
Krunkdog,

You picked up another infection since you posted your first logs. If it's at all possible, please keep this machine off the internet except to work with me here.

🖼Click to load external image (Posted Image) Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Documents and Settings\Michael\Local Settings\Application Data\ave.exe ()
    [2010/04/15 21:58:13 | 000,192,512 | -HS- | C] () – C:\Documents and Settings\Michael\Local Settings\Application Data\ave.exe
    [2010/04/15 21:58:13 | 000,016,824 | -HS- | C] () – C:\Documents and Settings\Michael\Local Settings\Application Data\21a34KM55vORW
    [2010/04/15 19:23:43 | 000,016,824 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\21a34KM55vORW
    [2010/04/15 19:23:43 | 000,016,638 | -HS- | C] () – C:\Documents and Settings\NetworkService\Local Settings\Application Data\21a34KM55vORW
    O37 - HKLM\…exe [@ = secfile] – "C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe" /START "%1" %* File not found
    O37 - HKCU\…exe [@ = secfile] – "C:\Documents and Settings\Michael\Local Settings\Application Data\ave.exe" /START "%1" %* ()
    
    :Files
    C:\Documents and Settings\Michael\Local Settings\Application Data\ave.exe
    C:\Program Files\SUPERAntiSpyware\superantispyware.exe|C:\Program Files\SUPERAntiSpyware\superantispyware .exe /replace
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe|C:\Program Files\Windows Live\Messenger\msnmsgr .exe /replace
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "msnmsgr="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"
  • Then click the Run Fix button at the top
  • Let the program run unhindered, it will reboot when it is done and produce a log
🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • OTL fix log
  • ComboFix log
After I ran combofix and my computer rebooted I was for some reason not able to connect to the Internet anymore I'm currently having to type this from my iPod. Any way to fix this?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI