This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Friend's HJT log

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have once again had a friend ask me for help with a malware issue. This time the issue is with a netbook and one possibility she hasn't ruled out is deliberate sabotage by her husband (they're separated and there's a lot of drama).

Anyway, I ran MBAM and found like 38 things wrong before Norton popped up, having found #39, insisting on rebooting the machine to facilitate its removal. I decided to reboot in safe mode which I'm posting this from, and ran HJT. I'll do another MBAM scan right away as well. Meanwhile, here's what HJT has to say for itself. (Note that she's been removing stuff via HJT on advice from another site, I warned her that was unlikely to permanently resolve most issues.)


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:32:14 PM, on 27/07/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Opera\opera.exe
C:\Documents and Settings\Administrator.BRENNABOOK\Local Settings\Application Data\Opera\Opera\temporary_downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eeepc.asus.com/global
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [AsusACPIServer] C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
O4 - HKLM\..\Run: [AsusEPCMonitor] C:\Program Files\EeePC\ACPI\AsEPCMon.exe
O4 - HKLM\..\Run: [AsusTray] C:\Program Files\EeePC\ACPI\AsTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynAsusAcpi] C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\WINDOWS\AsScrPro.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [STrHH] C:\Documents and Settings\Brenna.BRENNABOOK\dfdfdf.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Eee Docking] C:\Program Files\ASUS\Eee Docking\Eee Docking.exe
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe

–
End of file - 6230 bytes


*****************************************************
EDIT: Here is the log from running MBAM post-reboot. It found tons of stuff. I think the log is from just before I told it to fix everything it could.



Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4360

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 7.0.5730.13

27/07/2010 11:07:16 PM
mbam-log-2010-07-27 (23-07-16).txt

Scan type: Quick scan
Objects scanned: 143976
Time elapsed: 12 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 7
Files Infected: 73

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman (Trojan.Agent) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Program Files\Defense Center (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center (Rogue.DefenseCenter) -> No action taken.
C:\EQUITY\Q-5-6-99-222222CCCC-333333333333-7777777777-111 (Backdoor.IRCBot) -> No action taken.
C:\Recycle\P-1-3-64-8794238531-8742492-9897532 (Trojan.Agent) -> No action taken.
C:\Soft\G-414141ERER-1233211231-12313242131-555 (Worm.AutoRun) -> No action taken.
C:\TeekA\ANAS (Backdoor.Agent) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt (Trojan.DNSChanger) -> No action taken.

Files Infected:
C:\RECYCLER\S-1-5-21-0847472823-8338374939-518292446-5370\yv8g67.exe (Trojan.Proxy) -> No action taken.
C:\WINDOWS\system32\ernel32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\vryw.kco (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A3kUO3oC9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A55eI.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\A7kU17.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\a93eI93.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\AA3kUO3.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\C1s9eI7q.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\C5sKU.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\eI31q93.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\g31a931s9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\kU55i.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\KU9317.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\kUOC317y.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\mYWS9317y.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\OC1sKUOC9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\Q3wS9eIQG.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\s5eIQ.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\sKUOC7.dll (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\UO9o17.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\UOCE3a7k.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\uOCE3aA9.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\WSK93gMY.dll (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y3c7s317u.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y555m.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\spool\prtprocs\w32x86\y793m7.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\1PV3GWDA\401-direct[1].ex (Trojan.Agent.Gen) -> No action taken.
C:\WINDOWS\itrelsr.dll (Trojan.Hiloti) -> No action taken.
C:\WINDOWS\Ktirua.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirub.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktiruc.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirud.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirue.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktiruf.exe (Trojan.FraudPack) -> No action taken.
C:\WINDOWS\Ktirug.exe (Trojan.FraudPack) -> No action taken.
C:\Program Files\Defense Center\about.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\activate.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\buy.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\def.db (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\defext.dll (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\defhook.dll (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\help.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\scan.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\settings.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\splash.mp3 (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\Uninstall.exe (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\update.ico (Rogue.DefenseCenter) -> No action taken.
C:\Program Files\Defense Center\virus.mp3 (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\About.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Activate.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Buy.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Defense Center Support.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Defense Center.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Scan.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Settings.lnk (Rogue.DefenseCenter) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Start Menu\Programs\Defense Center\Update.lnk (Rogue.DefenseCenter) -> No action taken.
C:\EQUITY\Q-5-6-99-222222CCCC-333333333333-7777777777-111\Desktop.ini (Backdoor.IRCBot) -> No action taken.
C:\Recycle\P-1-3-64-8794238531-8742492-9897532\Desktop.ini (Trojan.Agent) -> No action taken.
C:\Soft\G-414141ERER-1233211231-12313242131-555\DeSkToP.ini (Worm.AutoRun) -> No action taken.
C:\TeekA\ANAS\Desktop.ini (Backdoor.Agent) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\pragmabbr.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAc.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAcfg.ini (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\pragmaserf.dll (Trojan.DNSChanger) -> No action taken.
C:\WINDOWS\PRAGMAgobxdcxnnt\PRAGMAsrcr.dat (Trojan.DNSChanger) -> No action taken.
C:\Documents and Settings\NetworkService\Application Data\dhxiuw.dat (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\config\systemprofile\Application Data\dhxiuw.dat (Malware.Trace) -> No action taken.
C:\Documents and Settings\All Users\Application Data\pragmamfeklnmal.dll (Rootkit.TDSS) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\Application Data\Microsoft\Internet Explorer\Quick Launch\Defense Center.LNK (Rogue.DefenseCenter) -> No action taken.
C:\WINDOWS\system32\sdra64.exe (Spyware.Zbot) -> No action taken.
C:\WINDOWS\system32\secupdat.dat (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\Brenna.BRENNABOOK\secupdat.dat (Worm.Autorun) -> No action taken.
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I let her know you'd responded about 24 hours ago, but I am currently in a different city than her and don't know if she's acted on this knowledge yet. I have encouraged her to make an account of her own and sign up here for further assistance, but I don't know if or when she plans on doing so.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI