This thing will not go away……Ive scanned with just about everything over and over, and according only to Ewido it is still there……..The following is a step by step of my latest attempt……
(all programs are up to date)
1. Ran TrendMicro Housecall…………….found Nothing
2. Ran eTrust Antivirus web scan……….found Nothing
3. Ran Panda Activescan………………….found Nothing
4. Ran Spybot……………..found some spyware items and cleaned them
5. Ran AdAware…………………….found Nothing
6. Ran CWShredder…………………found Nothing
7. Ran Ewido……………….found the trojan, plus other items (see log below)
8. Ran Regedit, searched for jjaa…………found Nothing
9. Deleted Recycle Bin, Turned off System restore, then rebooted.
10. Once I rebooted, I reran Ewido………found the trojan Again! (as a test, I didnt remove the trojan, and again searched Regedit for jjaa…..but did not find anything this time, but for all I know I can search the registry again in 20 mins and Ill get those two entries that Ive found before (see prior posts)
***NOTE***
What ever this thing is, and whatever it does…….all I can say is that it doesnt appear to be affecting my system performance, its just very worrisome that something is on my PC and I dont know what its doing. Its in my opinion that this trojan exploits Internet Explorer, and downloads adware/spyware when you use IE. I no longer use IE for that very reason, I use Firefox….but I came to that hypothesis because Spybot found a bunch of junk it never had before, only after I used the three online virus scans you recommended, which I had to run through Internet Explorer.
What is your opinion?
Does my Hijackthis log look clean?
What else can I do?
Your help is greatly appreciated!
Logfile of HijackThis v1.99.1
Scan saved at 7:16:29 PM, on 9/27/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\devldr32.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Smalls\Desktop\Fix\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} (Microsoft VM) - file://D:\GAMES\msjavx86_3805.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
http://www.creative.com/su/ocx/12119/CTSUEng.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
http://tools.ebayimg.com/eps/wl/activex/EP…l_v1-0-3-17.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) -
http://www.creative.com/su/ocx/15008/CTPID.cab
O16 - DPF: {F992FDC0-DAA7-4774-B01C-E9DFF19FE0FE} (Invoke Solutions MILive Participant Control(MR)) -
http://online.invokesolutions.com/events/b…7203/MILive.cab
O16 - DPF: {FA13A9FA-CA9B-11D2-9780-00104B242EA3} - file://D:\GAMES\WebDriverFullInstall.exe
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) -
http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
———————————————————
ewido security suite - Scan report
———————————————————
+ Created on: 11:36:59 PM, 9/26/2005
+ Report-Checksum: BC28E36D
+ Scan result:
:mozilla.6:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.7:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.8:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.9:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned without backup
:mozilla.28:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.29:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned without backup
:mozilla.51:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned without backup
:mozilla.60:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned without backup
:mozilla.61:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned without backup
:mozilla.62:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.63:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned without backup
:mozilla.64:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup
:mozilla.65:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup
:mozilla.66:C:\Documents and Settings\Smalls\Application Data\Mozilla\Firefox\Profiles\npd5cmlj.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned without backup
C:\WINDOWS\system32:jjaa.dll -> TrojanDownloader.Small.azk : Cleaned without backup
::Report End