This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HijackThis - my infected computer

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I am infected and need help. I ran Spybot and AdAware, and then rebooted. I then ran HijackThis. Any help would be much appreciated. Here is the logfile:


Logfile of HijackThis v1.99.1
Scan saved at 10:54:34 PM, on 6/22/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Connected\AgentSrv.EXE
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\PROGRA~1\NavNT\NavRoam.exe
c:\PROGRA~1\NavNT\Rtvscan.exe
C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
C:\Program Files\Support.com\bin\tgsrvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\winnt\system32\wscript.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\WINNT\System32\PSof1.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINNT\System32\kmlrjk.exe
c:\winnt\system32\numevu.exe
C:\WINNT\system\jkcmordrww.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Documents and Settings\nbksso8\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://flagscape.bankofamerica.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /nf /server
O4 - HKLM\..\Run: [Userstate] c:\winnt\system32\wscript.exe "c:\program files\bank of america\userstate\logonmonitor.vbs"
O4 - HKLM\..\Run: [SwdisUsrPCN.B00114343A4D5] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\\FaxCtrl.exe
O4 - HKLM\..\Run: [Visual Mortgage Loanline Universal Config 20.04.10.13] C:\Program Files\Bank of America\VM 3.0\Bloomington\stub.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [PSof1] C:\WINNT\System32\PSof1.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [exp] C:\WINNT\System32\exp
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\kmlrjk.exe reg_run
O4 - HKLM\..\Run: [checkrun] C:\winnt\system32\eliteizj32.exe
O4 - HKLM\..\Run: [dmuzbg] c:\winnt\system32\numevu.exe r
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O4 - Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - c:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://insite.bankofamerica.com
O15 - Trusted Zone: *.bankofamerica.com
O15 - Trusted Zone: *.knowledgenet.com
O15 - Trusted Zone: *.bankofamerica.com (HKLM)
O15 - Trusted Zone: *.knowledgenet.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0002.exe
O16 - DPF: {C45BF871-461C-11D5-81C5-0050DAC7A70C} - http://reportshop.bankofamerica.com/cab/datashop.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\Software\..\Telephony: DomainName = mn.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O20 - Winlogon Notify: NavLogon - c:\WINNT\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\Connected\AgentSrv.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - c:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Domain Time Client - Greyware Automation Products, Inc. - c:\winnt\system32\domtimec.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: NAVRoam - symantec - C:\PROGRA~1\NavNT\NavRoam.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - c:\PROGRA~1\NavNT\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\RapApp.exe
O23 - Service: Extend360 Agent (ServiceMgr) - Fiberlink Communications Corp. - C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
O23 - Service: Support.com Repair Service - Support.com, Inc. - C:\Program Files\Support.com\bin\tgsrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINNT\svcproc.exe
Download this tool: LQfix.zip
Unzip it to your Desktop.
Don't use it yet!

The above Registry file was written specifically for this infection and is not to be used on any other infection as it could damage a person's PC

IMPORTANT! Reboot the computer into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').

Doubleclick LQfix.bat that you saved on your desktop before.
A doswindow will open and close again, that is normal.

Reboot into normal mode and scan with HijackThis. Post the new log as a reply to this thread.
Okay, I ran the batch file in Safe Mode. Then I rebooted, and scanned with Hijack This. Here is the resulting log file:


Logfile of HijackThis v1.99.1
Scan saved at 1:37:56 PM, on 6/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Connected\AgentSrv.EXE
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\PROGRA~1\NavNT\NavRoam.exe
c:\PROGRA~1\NavNT\Rtvscan.exe
C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
C:\Program Files\Support.com\bin\tgsrvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\winnt\system32\wscript.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\WINNT\System32\PSof1.exe
C:\WINNT\System32\kmlrjk.exe
C:\WINNT\system\jkcmordrww.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Connected\CBSysTray.exe
C:\Documents and Settings\nbksso8\Desktop\My Briefcase\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://flagscape.bankofamerica.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
F2 - REG:system.ini: Shell=Explorer.exe C:\WINNT\Nail.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /nf /server
O4 - HKLM\..\Run: [Userstate] c:\winnt\system32\wscript.exe "c:\program files\bank of america\userstate\logonmonitor.vbs"
O4 - HKLM\..\Run: [SwdisUsrPCN.B00114343A4D5] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\\FaxCtrl.exe
O4 - HKLM\..\Run: [Visual Mortgage Loanline Universal Config 20.04.10.13] C:\Program Files\Bank of America\VM 3.0\Bloomington\stub.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [PSof1] C:\WINNT\System32\PSof1.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [exp] C:\WINNT\System32\exp
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\kmlrjk.exe reg_run
O4 - HKLM\..\Run: [zojtvre] c:\winnt\system32\iggpzeb.exe r
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O4 - Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - c:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://insite.bankofamerica.com
O15 - Trusted Zone: *.bankofamerica.com
O15 - Trusted Zone: *.knowledgenet.com
O15 - Trusted Zone: *.bankofamerica.com (HKLM)
O15 - Trusted Zone: *.knowledgenet.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0002.exe
O16 - DPF: {C45BF871-461C-11D5-81C5-0050DAC7A70C} - http://reportshop.bankofamerica.com/cab/datashop.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\Software\..\Telephony: DomainName = mn.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O20 - Winlogon Notify: NavLogon - c:\WINNT\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\Connected\AgentSrv.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - c:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Domain Time Client - Greyware Automation Products, Inc. - c:\winnt\system32\domtimec.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: NAVRoam - symantec - C:\PROGRA~1\NavNT\NavRoam.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - c:\PROGRA~1\NavNT\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\RapApp.exe
O23 - Service: Extend360 Agent (ServiceMgr) - Fiberlink Communications Corp. - C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
O23 - Service: Support.com Repair Service - Support.com, Inc. - C:\Program Files\Support.com\bin\tgsrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINNT\svcproc.exe
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

Please download Nailfix from here:
http://www.noidea.us/easyfile/file.php?sho…050515010747824
Unzip it to the desktop but please do NOT run it yet.

The above Registry file written by miekiemoes, Swandog and racooper was written specifically for this infection and is not to be used on any other infection as it could damage a person's PC

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml

Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly — this is normal.

Then please run Ewido, and run a full scan. Save the log from the scan to your Desktop. IMPORTANT! Lately more people choose “Ignore” during the scan, but you’ll have to click/choose “Clean” or “Quarantine”! Otherwise the whole fix will result in a failure.

Then please run HijackThis, click Scan, and check (if there):

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

Close all open windows except for HijackThis and click Fix Checked.

Restart your computer in normal mode, make a new HijackThis log and post it here, as well as the log from the Ewido scan.
Okay, I followed the directions below, scanned with Ewido in Safe Mode (log below), scanned with HijackThis in Safe Mode, and then rebooted, and scanned again with HijackThis in normal mode (log below).

HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 8:57:30 PM, on 6/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Connected\AgentSrv.EXE
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\PROGRA~1\NavNT\NavRoam.exe
c:\PROGRA~1\NavNT\Rtvscan.exe
C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
C:\Program Files\Support.com\bin\tgsrvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\winnt\system32\wscript.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\WINNT\System32\PSof1.exe
C:\WINNT\System32\kmlrjk.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Connected\CBSysTray.exe
C:\Documents and Settings\nbksso8\Desktop\My Briefcase\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://flagscape.bankofamerica.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /nf /server
O4 - HKLM\..\Run: [Userstate] c:\winnt\system32\wscript.exe "c:\program files\bank of america\userstate\logonmonitor.vbs"
O4 - HKLM\..\Run: [SwdisUsrPCN.B00114343A4D5] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\\FaxCtrl.exe
O4 - HKLM\..\Run: [Visual Mortgage Loanline Universal Config 20.04.10.13] C:\Program Files\Bank of America\VM 3.0\Bloomington\stub.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [PSof1] C:\WINNT\System32\PSof1.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\kmlrjk.exe reg_run
O4 - HKLM\..\Run: [zojtvre] c:\winnt\system32\iggpzeb.exe r
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O4 - Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - c:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://insite.bankofamerica.com
O15 - Trusted Zone: *.bankofamerica.com
O15 - Trusted Zone: *.knowledgenet.com
O15 - Trusted Zone: *.bankofamerica.com (HKLM)
O15 - Trusted Zone: *.knowledgenet.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0002.exe
O16 - DPF: {C45BF871-461C-11D5-81C5-0050DAC7A70C} - http://reportshop.bankofamerica.com/cab/datashop.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\Software\..\Telephony: DomainName = mn.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O20 - Winlogon Notify: NavLogon - c:\WINNT\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\Connected\AgentSrv.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - c:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Domain Time Client - Greyware Automation Products, Inc. - c:\winnt\system32\domtimec.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: NAVRoam - symantec - C:\PROGRA~1\NavNT\NavRoam.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - c:\PROGRA~1\NavNT\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\RapApp.exe
O23 - Service: Extend360 Agent (ServiceMgr) - Fiberlink Communications Corp. - C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
O23 - Service: Support.com Repair Service - Support.com, Inc. - C:\Program Files\Support.com\bin\tgsrvc.exe


Ewido Scan Log:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 8:48:22 PM, 6/28/2005
+ Report-Checksum: 1BA7184E

+ Date of database: 6/28/2005
+ Version of scan engine: v3.0

+ Duration: 14 min
+ Scanned Files: 52879
+ Speed: 60.64 Files/Second
+ Infected files: 14
+ Removed files: 14
+ Files put in quarantine: 14
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0

+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes

+ Scanned items:
C:\

+ Scan result:
C:\Documents and Settings\nbksso8\Desktop\My Briefcase\HijackThis\backups\backup-20050622-221938-527.dll -> Spyware.BookedSpace.e -> Cleaned with backup
C:\Program Files\Aprps\CxtPls.dll -> TrojanDownloader.Apropo.ad -> Cleaned with backup
C:\WINNT\Downloaded Program Files\installer_MARKETING14.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\WINNT\system\jkcmordrww.exe -> TrojanDownloader.Small.ayh -> Cleaned with backup
C:\WINNT\system32\cdapp\yenhttludb.dll -> Spyware.SmartPops -> Cleaned with backup
C:\WINNT\system32\cdapp\yenhttludb.exe -> Spyware.SmartPops -> Cleaned with backup
C:\WINNT\system32\dist001.exe -> TrojanDownloader.Agent.qg -> Cleaned with backup
C:\WINNT\system32\exp -> TrojanDownloader.Small.abd -> Cleaned with backup
C:\WINNT\system32\iM49.exe -> TrojanDownloader.Adload.a -> Cleaned with backup
C:\WINNT\system32\nsfDB.dll -> Spyware.HotSearchBar -> Cleaned with backup
C:\WINNT\system32\redit.cpl -> TrojanDownloader.Qoologic.p -> Cleaned with backup
C:\WINNT\system32\supdate.dll -> TrojanDownloader.Qoologic.p -> Cleaned with backup
C:\WINNT\system32\uci.exe -> TrojanDropper.Agent.hl -> Cleaned with backup
C:\WINNT\tvbpkbbqg.exe -> Spyware.BetterInternet -> Cleaned with backup


::Report End
If running Windows XP Pro: run this tool http://homepage.ntlworld.com/spencer.greys…/XPProfiles.exe

If running Windows XP Home: run this tool http://homepage.ntlworld.com/spencer.greys…XPHomeFiles.exe

(Running the tool is just extracting the files to the already specified location and closing the tool)

Reboot.

Download the FindQoologic-Narrator.zip and save it to your Desktop.
http://forums.net-integration.net/index.ph…=post&id=134981

The above files written by O_E were written specifically for this infection and is not to be used on any other infection as it could damage a person's PC

1. Extract (unzip) the files inside into their own folder called FindQoologic.
2. Open the FindQoologic folder.
3. Locate and double-click the Find-Qoologic2.bat to run it.

* The tool will open a DOS window and begin to check your system.
When it is finished a text file will open in Notepad called "file.txt".
* Save this text file in the FindQoologic folder.
* Close the DOS box If on win 98 or me.

4. Open the file you saved and copy / paste its content to this thread (as a reply).
I followed the directions below. When I finally ran the Find-Qoologic2.bat file, I received some error messages about running DOS with Windows. Anyway, here is the resulting text file: PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. some examples are MRT.EXE NTDLL.DLL. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48 Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. Acrobat Assistant.lnk Connected TaskBar Icon.LNK desktop.ini dtun.exe User Startup: C:\Documents and Settings\nbksso8\Start Menu\Programs\Startup . .. Connected TaskBar Icon.LNK desktop.ini »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido REG_SZ {57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\gqsfngsf REG_SZ {ed9e4383-26e4-44d7-adf1-561d377f5570} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu REG_SZ {BDA77241-42F6-11d0-85E2-00AA001FE28C} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip REG_SZ {E0D79304-84BE-11CE-9641-444553540000} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} REG_SZ Start Menu Pin
Hi Hans, thanks for the help so far. The problem was the XPProfiles.exe unzipped to C:\Windows\system32 and my system files are in C:\WINNT\system32. I made the correction, and I think we're back on track. I was able to run FindQoologic, and here is the resulting log file: PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. some examples are MRT.EXE NTDLL.DLL. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» * KavSvc C:\WINNT\System32\EUYRPEY.DLL * KavSvc C:\WINNT\System32\RNGUW.DLL * aspack C:\WINNT\System32\QVGPA.DAT * aspack C:\WINNT\System32\COXBNCX.EXE * aspack C:\WINNT\System32\KMLRJK.EXE * aspack C:\WINNT\System32\EUYRPEY.DLL * aspack C:\WINNT\System32\RNGUW.DLL * UPX! C:\WINNT\System32\PSOF1.EXE »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» * exe C:\docume~1\alluse~1\startm~1\programs\startup\DTUN.EXE »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48 Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. Acrobat Assistant.lnk Connected TaskBar Icon.LNK desktop.ini dtun.exe User Startup: C:\Documents and Settings\nbksso8\Start Menu\Programs\Startup . .. Connected TaskBar Icon.LNK desktop.ini »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido REG_SZ {57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\gqsfngsf REG_SZ {ed9e4383-26e4-44d7-adf1-561d377f5570} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu REG_SZ {BDA77241-42F6-11d0-85E2-00AA001FE28C} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip REG_SZ {E0D79304-84BE-11CE-9641-444553540000} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} REG_SZ Start Menu Pin
Download Killbox.
Click killbox.exe.
Select the option "Delete on reboot".

Now copy the next bold:

C:\WINNT\System32\EUYRPEY.DLL
C:\WINNT\System32\QVGPA.DAT
C:\WINNT\System32\COXBNCX.EXE
C:\WINNT\System32\KMLRJK.EXE
C:\WINNT\System32\EUYRPEY.DLL
C:\WINNT\System32\RNGUW.DLL
C:\WINNT\System32\PSOF1.EXE
C:\docume~1\alluse~1\startm~1\programs\startup\DTUN.EXE


Open 'file' in the killboxmenu on top and choose Paste from clipboard

Now you will see, this is pasted in the "Full Path of File to Delete"-field.
There's a little arrow (dropdown-arrow) next to that field.
If you expand it, these lines must be there together!

Then press the button that looks like a red circle with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.. Click YES
When it asks if you would like to Reboot now, click YES
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.

Your system must reboot now.

Open notepad and copy and paste next content in the field in it:

REGEDIT4

[-HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\gqsfngsf]

The above Registry file was written specifically for this infection on this person's computer. It is NOT to be used on another computer, as it may cause damage that could result in a format.

Save this as Qfix.reg choose to save as *all files and place it on your desktop.
Doubleclick on it and when it asks you to add the content to the registry, click yes/ok

Post a new findqoologic-log in your next reply.
I ran Killbox, pasted the bold file paths below, and deleted upon reboot. I ran the Qfix.reg, then ran findqoologic and here is the resulting log file: PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED PLEASE BE CAREFUL WHILE FIXING. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE. some examples are MRT.EXE NTDLL.DLL. »»»»»»»»»»»»»»»»»»»»»»»» Files found »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» startup files»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» »»»»»»»»»»»»»»»»»»»»»»»» Checking Global Startup »»»»»»»»»»»»»»»»»»»»»» (fstarts by IMM - test ver. 0.001) NOT using address check – 0x77f5bd48 Global Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup . .. Acrobat Assistant.lnk Connected TaskBar Icon.LNK desktop.ini User Startup: C:\Documents and Settings\nbksso8\Start Menu\Programs\Startup . .. Connected TaskBar Icon.LNK desktop.ini »»»»»»»»»»»»»»»»»»»»»»»» Registry Entries Found »»»»»»»»»»»»»»»»»»»»»»» ! REG.EXE VERSION 3.0 HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido REG_SZ {57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu REG_SZ {BDA77241-42F6-11d0-85E2-00AA001FE28C} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files REG_SZ {750fdf0e-2a26-11d1-a3ea-080036587f03} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With REG_SZ {09799AFB-AD67-11d1-ABCD-00C04FC30936} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu REG_SZ {A470F8CF-A1E8-4f65-8335-227475AA5C46} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip REG_SZ {E0D79304-84BE-11CE-9641-444553540000} HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8} REG_SZ Start Menu Pin
New HijackThis log:


Logfile of HijackThis v1.99.1
Scan saved at 7:49:14 AM, on 6/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Connected\AgentSrv.EXE
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\PROGRA~1\NavNT\NavRoam.exe
c:\PROGRA~1\NavNT\Rtvscan.exe
C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
C:\Program Files\Support.com\bin\tgsrvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\winnt\system32\wscript.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Connected\CBSysTray.exe
C:\Documents and Settings\nbksso8\Desktop\My Briefcase\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://flagscape.bankofamerica.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /nf /server
O4 - HKLM\..\Run: [Userstate] c:\winnt\system32\wscript.exe "c:\program files\bank of america\userstate\logonmonitor.vbs"
O4 - HKLM\..\Run: [SwdisUsrPCN.B00114343A4D5] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\\FaxCtrl.exe
O4 - HKLM\..\Run: [Visual Mortgage Loanline Universal Config 20.04.10.13] C:\Program Files\Bank of America\VM 3.0\Bloomington\stub.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKLM\..\Run: [PSof1] C:\WINNT\System32\PSof1.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\kmlrjk.exe reg_run
O4 - HKLM\..\Run: [zojtvre] c:\winnt\system32\iggpzeb.exe r
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O4 - Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - c:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://insite.bankofamerica.com
O15 - Trusted Zone: *.bankofamerica.com
O15 - Trusted Zone: *.knowledgenet.com
O15 - Trusted Zone: *.bankofamerica.com (HKLM)
O15 - Trusted Zone: *.knowledgenet.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0002.exe
O16 - DPF: {C45BF871-461C-11D5-81C5-0050DAC7A70C} - http://reportshop.bankofamerica.com/cab/datashop.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\Software\..\Telephony: DomainName = mn.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O20 - Winlogon Notify: NavLogon - c:\WINNT\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\Connected\AgentSrv.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - c:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Domain Time Client - Greyware Automation Products, Inc. - c:\winnt\system32\domtimec.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: NAVRoam - symantec - C:\PROGRA~1\NavNT\NavRoam.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - c:\PROGRA~1\NavNT\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\RapApp.exe
O23 - Service: Extend360 Agent (ServiceMgr) - Fiberlink Communications Corp. - C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
O23 - Service: Support.com Repair Service - Support.com, Inc. - C:\Program Files\Support.com\bin\tgsrvc.exe
Hi,

1. Run HijackThis (“Do a system scan only”). Put a checkmark near these lines:

O4 - HKLM\..\Run: [PSof1] C:\WINNT\System32\PSof1.exe
O4 - HKLM\..\Run: [VBouncer] C:\PROGRA~1\VBouncer\VirtualBouncer.exe
O4 - HKLM\..\Run: [cfgmgr52] RunDLL32.EXE C:\WINNT\cfgmgr52.dll,DllRun
O4 - HKLM\..\Run: [KavSvc] C:\WINNT\System32\kmlrjk.exe reg_run
O4 - HKLM\..\Run: [zojtvre] c:\winnt\system32\iggpzeb.exe r

O16 - DPF: {972BB342-14A7-4660-83C1-51DDBEE171DB} - http://www.pacimedia.com/install/pcs_0002.exe


2. Close all other windows and browsers, and hit Fix Checked.

3. Reboot into safe mode by tapping F8 frequently during bootup.
Make sure your settings allow you to view "Hidden files". Open up any explorer windows and click on "Tools" => "Folder Options" => "View" and be sure to check off "Show Hidden Files and Folders".

4. Delete, in safe mode:
Folder
C:\PROGRA~1\VBouncer

Files
C:\WINNT\System32\PSof1.exe
C:\WINNT\System32\kmlrjk.exe
c:\winnt\system32\iggpzeb.exe
C:\WINNT\cfgmgr52.dll

5. Reboot into normal mode, make a new HijackThis log, and post it here :)
I fixed the checked files, and then rebooted in Safe mode. I checked the Show Hidden Files and applied to all folders. I could not find the files you listed to delete (maybe Ad-Aware and Spybot got them a while ago?).

Anyway, I rebooted, and here is the HijackThis log:



Logfile of HijackThis v1.99.1
Scan saved at 4:31:01 PM, on 6/30/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\Ati2evxx.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Connected\AgentSrv.EXE
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\PROGRA~1\NavNT\DefWatch.exe
c:\winnt\system32\domtimec.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\PROGRA~1\NavNT\NavRoam.exe
c:\PROGRA~1\NavNT\Rtvscan.exe
C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
C:\Program Files\Support.com\bin\tgsrvc.exe
C:\WINNT\system32\Ati2evxx.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NavNT\vptray.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\winnt\system32\wscript.exe
C:\Program Files\RightFax\FaxCtrl.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Connected\CBSysTray.exe
C:\Documents and Settings\nbksso8\Desktop\My Briefcase\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://flagscape.bankofamerica.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://flagscape.bankofamerica.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxyconfig.bankofamerica.com
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [vptray] c:\PROGRA~1\NavNT\vptray.exe
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /nf /server
O4 - HKLM\..\Run: [Userstate] c:\winnt\system32\wscript.exe "c:\program files\bank of america\userstate\logonmonitor.vbs"
O4 - HKLM\..\Run: [SwdisUsrPCN.B00114343A4D5] "C:\PROGRA~1\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "C:\Program Files\Tivoli\swdis\1\wdusrpcn.env"
O4 - HKLM\..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files\RightFax\\FaxCtrl.exe
O4 - HKLM\..\Run: [Visual Mortgage Loanline Universal Config 20.04.10.13] C:\Program Files\Bank of America\VM 3.0\Bloomington\stub.exe
O4 - HKLM\..\Run: [AS00_Gear511] C:\Program Files\NETGEAR\WG511SCU\Utility\Gear511.exe -hide
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\temp\stubinstaller6480.exe"
O4 - Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Connected TaskBar Icon.LNK = C:\Program Files\Connected\CBSysTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - c:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://insite.bankofamerica.com
O15 - Trusted Zone: *.bankofamerica.com
O15 - Trusted Zone: *.knowledgenet.com
O15 - Trusted Zone: *.bankofamerica.com (HKLM)
O15 - Trusted Zone: *.knowledgenet.com (HKLM)
O16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cab
O16 - DPF: {C45BF871-461C-11D5-81C5-0050DAC7A70C} - http://reportshop.bankofamerica.com/cab/datashop.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\Software\..\Telephony: DomainName = mn.bankofamerica.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mn.bankofamerica.com
O20 - Winlogon Notify: NavLogon - c:\WINNT\System32\NavLogon.dll
O23 - Service: Connected Agent Service (AgentSrv) - Connected Corporation - C:\Program Files\Connected\AgentSrv.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - c:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DefWatch - Symantec Corporation - c:\PROGRA~1\NavNT\DefWatch.exe
O23 - Service: Domain Time Client - Greyware Automation Products, Inc. - c:\winnt\system32\domtimec.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: NAVRoam - symantec - C:\PROGRA~1\NavNT\NavRoam.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - c:\PROGRA~1\NavNT\Rtvscan.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\RapApp.exe
O23 - Service: Extend360 Agent (ServiceMgr) - Fiberlink Communications Corp. - C:\Program Files\Fiberlink\Mobile Access Services\ServiceMgr.exe
O23 - Service: Support.com Repair Service - Support.com, Inc. - C:\Program Files\Support.com\bin\tgsrvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI