This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New User

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm Christian, conservative and single. I was serching the web for conservative singles yesterday and one of the sites that seemed to be inocent wasn't. Porno came up everywhere. I could'nt get out! Things on my computer changed, like my toolbar, homepage etc. Things like power scan and purityscan among other things downloaded on my computer. I found your site and have been studying all day. I've downloaded spybot and the hijack - here are the results of hijack. I dont know very much about computers, i'm very concerned and need help Please!!! Thank you crockett

Attachments:

  • [attachment removed: hijackthis.log]
Hi crockett

you are best to copy paste the results in your post so everyone can see them

Logfile of HijackThis v1.97.7
Scan saved at 12:02:04 PM, on 12/29/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\gearsec.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\Program Files\Media\Media\UpdateStats.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\WINDOWS\uptodate.exe
C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\ClockSync\Sync.exe
C:\Program Files\BigFix\BigFix.exe
C:\WINDOWS\System32\WkvZ0635.exe
C:\WINDOWS\System32\XuoJ.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\AproposClient\Apropos.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Brian Dingle\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rr.com/v5/home/0,1793,141,00.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.ht…count_id=134168
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.rr.com/v5/home/0,1793,141,00.html
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_1/home.html"); (C:\Documents and Settings\Brian Dingle\Application Data\Mozilla\Profiles\default\uqcymn0i.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Brian Dingle\Application Data\Mozilla\Profiles\default\uqcymn0i.slt\prefs.js)
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {01C5BF6C-E699-4CD7-BEA1-786FA05C83AB} - C:\Program Files\AproposClient\AproposPlugin.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2CF0B992-5EEB-4143-99C0-5297EF71F443} - C:\WINDOWS\System32\stlbdist.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~2\BHO\INCFIN~1.DLL
O2 - BHO: (no name) - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem216.dll
O2 - BHO: (no name) - {EBB313B6-4FE0-4CC3-BB57-890F244BA59F} - C:\WINDOWS\System32\lftiga11n.dll
O2 - BHO: (no name) - {F7F808F0-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem214.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: toolbar - {FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} - C:\WINDOWS\Downloaded Program Files\toolbar.dll
O3 - Toolbar: Search - {2CF0B992-5EEB-4143-99C0-5297EF71F444} - C:\WINDOWS\System32\stlbdist.DLL
O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [UpdateStats] C:\Program Files\Media\Media\UpdateStats.exe
O4 - HKLM\..\Run: [LNX] C:\WINDOWS\LNX.exe
O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINDOWS\System32\stlbdist.DLL,DllRunMain
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [2N85L533MR#GJT] C:\WINDOWS\System32\Blj6ta7y.exe
O4 - HKLM\..\Run: [RunWindowsUpdate] C:\WINDOWS\uptodate.exe
O4 - HKLM\..\Run: [AutoUpdater] C:\PROGRA~1\AUTOUP~1\AUTOUP~1.EXE
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ClockSync] C:\Program Files\ClockSync\Sync.exe /q
O4 - HKLM\..\RunOnce: [Hardcore] C:\261639.bat
O4 - HKCU\..\RunOnce: [DeleteISTbar] rundll32.exe advpack.dll,DelNodeRunDLL32 "C:\Program Files\ISTbar\istbar.dll"
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra 'Tools' menuitem: Turbo Download (HKLM)
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… (HKLM)
O9 - Extra button: ICQ (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {28F00B0F-DC4E-11D3-ABEC-005004A44EEB} (Register Class) - http://content.hiwirenetworks.net/inbrowse…5.30/Hiwire.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/038e938b8708f9a7dc21/…ip/RdxIE601.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe
O16 - DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} (CCMPGui Class) - http://64.124.45.181/chaincast/proxy/CCMP.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
O16 - DPF: {D7107300-E42A-4C1C-84EB-4D783E58B88D} (DNInstallerOCX Class) - http://www.speechmachines.org/Installer/InstallerOCX.cab
O16 - DPF: {FB2961FD-DD24-4F8A-8A92-6F9325FF6F11} (toolbar) - http://www.supaseek.com/toolbar/toolbar.cab

:thumbup:
Well crockett, you have a few problems there, before we go further tho, you need to install hijackthis to it's own folder rather than a temp folder. create a Hijackthis folder in 'My documents' unzip/extract it to there. this gives us a recovery option.

Next you have the peper a trojan.

1. Use the uninstall tool - download from: http://home01.wxs.nl/~kleyn080/uninst.exe. Double click on uninst.exe, let it run and terminate.

2. Delete all the associated files with drpeper - download from http://www.mjc1.com/files/mo/drpeper.html. Double click drpepertobackup, it will self extract to C:. With the text in the box highlighted and the 'overwrite' existing files checked, click start.

3. Go to the file C:\drpeper\Find backup and Delete Peper files.vbs and double click.

4. A box will appear, copy and paste: XuoJ.exe and hit ok.

5. A second box will appear, copy and paste Blj6ta7y.exe and hit ok.

6. It will find all the files, delete them and will make backups in the same folder. It'll open a text file (Peper.txt) with the list of all files deleted. Make sure it is saved.
Download and install both Adaware and Spybot Search & Destroy.
Spybot search and destroy


Open AdAware and use the "Check for updates now" link to download and install the latest reference file. Exit and restart AdAware, and this time click the "Start" button. Make sure that "Perform system Smart-Scan" is selected and that "Activate In-depth Scan" has a check next to it. Then click the "Next" button.

After the scan is complete, click the "Next" button. Right-click in the Scanning Results window and click "Select all objects". Then click the "Next" button and confirm that you want to delete the selected entries.

Exit AdAware and reboot. Make sure nothing (new) seems broken.

Use the "Easy Mode" link from your start menu to start Spybot S&D. Click the "Search for updates" button, then the "Download Updates" button. After all updates are downloaded, click the "Search and Destroy" button, and then the "Check for problems" button. When the scan is complete, place a check next to anything marked in red, then click the "Fix selected problems" button.

Exit Spybot S&D and reboot.

Then rescan with HJT, post a new HJT log and the contents of the saved Peper.txt file - the next stage will be to remove the rest of the bad stuff.
Hi Mark, First - thank you for your reply, I put the highjack in it's own folder. Then i downloaded the uninstall (a couple of times) and it wont let me open and run! again - i dont know alot about computers, so what am i doing wrong? Please help! crockett
OK - I went to step 2 and downloaded http://www.mjc1.com/files/mo/drpeper.html. when i doubleclick on it, it gave me this, i cant get it to work!


Use to ID and delete Peper Trojan files. *******************************************************************************
You will have two sets of Trojan Files.
Enter first known Trojan name.
The script will find any copies in your system or system32 folder (OS dependent) and delete them.
It will then ask for another name to get the second set and remove those.
It will list the names of the files it deletes in a logfile named Peper.txt
Peper.txt will be found in the same folder as this script
Backups of deleted files will be created in folder too.
Do not use this script on the desktop.
Create a folder for this script. The default folder will be c:\drpeper

Use at your own risk
********************************************************************************

Download:

This version makes a backup and renames the files.
The backup is made to the same directory the script is run from.
drpepertobackup.exe
I not sure, when i click on the link it does'nt want to download and i had to save target as - well anyway it's in my files, or so it seems - there's an icon there!
Ok double click the downloaded file, then use search to find the drpeper folder, double click it, it should open showing 2 files/folders , 1 is a vbs script icon (looks like an s) double click that. I will open a box, enter XuoJ.exe into it and hit ok it will then open a box again enter Blj6ta7y.exe and hit ok. post back once done
sorry to be such a pest - but i did what you said but every time i doubleclick on any of them in the search area it goes back to the internet link i preveously sent you.
crockett

sorry to be such a pest

no problem we will beat this <_<

Ok ,bottom left of the download page there is a drpepertobackup.exe is that what you are clicking on when you download ?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI