Cant Get Rid Of It
5 min read
StartupList report, 9/27/2004, 11:44:41 PM
StartupList version: 1.52
Started from : D:\MC\Temp\StartupList.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\PROGRA~1\Ahead\NEROTO~1\DRIVES~1.EXE
C:\WINDOWS\htpatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\AnVir Virus Destroyer\AnVir.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Messenger\msmsgs.exe
D:\MC\Temp\StartupList.exe
————————————————–
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
gwum.lnk = C:\Program Files\Gigabyte\Gigabyte Windows Utility Manager\gwum.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
Spy Sweeper.lnk = C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
————————————————–
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
————————————————–
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Zone Labs Client = C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
Nero DriveSpeed = C:\PROGRA~1\Ahead\NEROTO~1\DRIVES~1.EXE
————————————————–
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
msnmsgr = "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
Mozilla Quick Launch = "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
H/PC Connection Agent = "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
Symantec NetDriver Monitor = C:\PROGRA~1\SYMNET~1\SNDMon.exe
AnVir Virus Destroyer = "C:\Program Files\AnVir Virus Destroyer\AnVir.exe" Minimized
Yahoo! Pager = C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
SpySweeper = "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
NvMediaCenter = RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
————————————————–
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\xpvss.scr
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
————————————————–
Enumerating Browser Helper Objects:
(no name) - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINDOWS\System32\ctadl2.dll - {AEFCDEC8-EB7D-429F-BC73-4F30D07BFE41}
(no name) - C:\Program Files\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
————————————————–
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer.job
Symantec NetDetect.job
————————————————–
Enumerating Download Program Files:
[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab
[MSSecurityAdvisor Class]
InProcServer32 = C:\WINDOWS\System32\mssecadv.dll
CODEBASE = http://download.microsoft.com/download/0/5…b?1093447994046
[Web P2P Installer]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll
[YInstStarter Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\yinsthelper.dll
CODEBASE = http://download.yahoo.com/dl/installs/yinst0401.cab
[RdxIE Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\RdxIE.dll
CODEBASE = http://software-dl.real.com/2787267ca022b5…ip/RdxIE601.cab
[DialerWeb Class]
InProcServer32 = C:\WINDOWS\DOWNLO~1\WEBREC~1.DLL
CODEBASE = http://212.145.159.194/251065/dialercab/WebRecomendada.cab
[WUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\wuweb.dll
CODEBASE = http://v5.windowsupdate.microsoft.com/v5co…b?1093447325402
[ctadlctrl Class]
InProcServer32 = C:\WINDOWS\System32\ctadl2.dll
CODEBASE = http://www.clicktracking.info/ctadl1.cab
[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/…8003.5143055556
[YAddBook Class]
InProcServer32 = C:\PROGRA~1\Yahoo!\Common\yaddbook.dll
CODEBASE = http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwa…ash/swflash.cab
[{EF86873F-04C2-4A95-A373-5703C08EFC7B}]
CODEBASE = http://www.xxxtoolbar.com/ist/softwares/v3.0/0006.cab
————————————————–
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\Martin\LOCALS~1\Temp\A~NSISu_.exe||C:\DOCUME~1\Martin\LOCALS~1\Temp\A~NSISu_.exe||C:\DOCUME~1\Martin\LOCALS~1\Temp\_iu14D2N.tmp||C:\PROGRA~1\MyWay\myBar\2.bin\MYBAR.DLL||C:\PROGRA~1\MyWay\myBar\2.bin|||\
————————————————–
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
————————————————–
End of report, 8,300 bytes
Report generated in 1.094 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Yes, please.what is a "normal" log file? you mean from via hijackthis?
If the log isn't that far "out of whack", maybe just one or two fixes will get you back to the point you can use it normally.
Check ALL the lines that begin with:
O1 - Hosts
Check the line that says:
[Network Service] C:\windows\svhost.exe -sr -0
Check the one line that begins with:
O6
Then click "Fix checked"
Reboot in safe mode.
Find and delete:
C:\windows\svhost.exe <— file
Reboot in normal mode and try Hijack This!
Are things "better" now?
A link about that piece of malware:
(also explains how you got it)
Svhost.exe
Here's my list of things you can do to help prevent infection (at the end of this post).
Could you please post another log file so we can be sure you're "good to go"?
The picture you sent was a bit difficult to read. My eyes aren't what they used to be.
Items you may wish to consider to harden your defenses against future infections:
Read "How did I get infected in the first place?" here:
http://boards.cexx.org/viewtopic.php?t=957
Download IE-Spyad here:
https://netfiles.uiuc.edu/ehowes/www/resource.htm
IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.
Check your browser settings here:
http://browsercheck.qualys.com/index.php
A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.
Follow safe Internet practices:
1. Keep your virus definitions up to date, and scan your system regularly.
2. Don't open email, or download attachments from unrecognized email addresses.
3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.
4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.
5. Keep your Windows and IE current with all the latest patches and updates.
(Personally I'm NOT recommending SP2 for XP at this time)
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI