This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Another HJT LOG!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hullo, am having troubles with a particulary difficult virus that dosent want to shift,
-> C:\WINDOWS\system32\1024\ld78D0.tmp\[Upack] :angry: its wraking havoc.. well it was Avast seems to be keeping it under control at the mo but it cant get rid of it, any help would be greatly appreciated.

Thankyou

B.Cooper :blink:

oh and here is my logfile :)

Logfile of HijackThis v1.99.1
Scan saved at 19:09:23, on 10/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Bradley\Local Settings\Temporary Internet Files\Content.IE5\8LQN4HMN\spybotsd14[1].exe
C:\DOCUME~1\Bradley\LOCALS~1\Temp\is-QFL5H.tmp\is-G749P.tmp
C:\WINDOWS\explorer.exe
C:\DOCUME~1\Bradley\LOCALS~1\Temp\is-LL5SC.tmp\spybotsd_includes.exe
C:\Program Files\MyStuff\Software\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000000-0000-0000-0000-100000000003} - http://code.trasferimento.biz/l/4066c522b9…c893f5de_35.exe
O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} - http://promo.dollarrevenue.com/activex/pro…436342D2D2D.exe
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
Hello MrScruff, and welcome to TomCoyote forums. I'm dak, and I'll be helping you to fix your computer.

I'm sorry for the delay in replying to your log. If you still require assistance, please could you do the following:

Firstly, you have two anti-viruses running, which will just argue amongst each other and prevent each other from working, so i'd reccomend removing one of them by going to start > settings > controll pannell > add/remove software, and uninstalling either AVG or avast.


Scan again with HijackThis and post the new log as a reply to this thread.

Could you also do the following:
  • run HijackThis and click on the "Open the misc tools section".
  • Next, Click on "open uninstall manager"
  • Then Click "save list". This should create a log called "uninstall_list.txt".
Please post the contents of "uninstall_list.txt", along with a new HijackThis log, as a reply to this thread.
New HJT log –>

Logfile of HijackThis v1.99.1
Scan saved at 13:35:38, on 21/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MyStuff\Software\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000000-0000-0000-0000-100000000003} - http://code.trasferimento.biz/l/4066c522b9…c893f5de_35.exe
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

umm.. when i click on the save list button HJT just closes :blink: … i dont know quite what to do, any reccomendations??

Many Thanks B.Cooper ;)
Okey dokey, first off:

Run HijackThis, and place a check-mark next to the following:

O16 - DPF: {00000000-0000-0000-0000-100000000003} - http://code.trasferimento.biz/l/4066c522b9…c893f5de_35.exe

O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123


Then, with all other windows closed (including this one), click 'fix selected'.

Next, Please do an online scan with Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.


Finally, to test a theory can you please right-click on the 'hijackthis.exe' file and rename it to 'banana.exe'.

Please make a new HijackThis log, and post it and the kaspersky log up as a reply to this thread.

Also, could you see if you can get an uninstall list now that HijackThis has been renamed. If you can't, it doesnt matter that much.
HA! you're good! B) I like the banana rename and yes miraculously it works….. maybe it likes bananas… anywho here is the uninstal list–>

Ad-Aware SE Personal
Adobe Flash Player 9 ActiveX
Adobe Reader 7.0.8
ATI Display Driver
AVG Free Edition
BitLord 1.1
Call of Duty® 2
DivX
DivX Converter
DivX Player
DivX Web Player
ewido anti-spyware 4.0
HijackThis 1.99.1
J2SE Runtime Environment 5.0 Update 3
Kaspersky On-line Scanner
LimeWire 4.12.3
Microsoft Office Professional Edition 2003
Mozilla Firefox (1.5)
PowerISO
QuickTime
Rome - Total War™
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913433)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Spybot - Search & Destroy 1.4
Uniblue Registry Booster
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Service Pack 2
Worms World Party

and heres the Kapersky log –>

Monday, July 24, 2006 8:22:18 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 24/07/2006
Kaspersky Anti-Virus database records: 209586


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 59841
Number of viruses found 5
Number of infected objects 4
Number of suspicious objects 1
Duration of the scan process 01:22:47

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Bradley\Local Settings\Temp\mst6C.tmp Infected: Packed.Win32.Klone.g skipped

C:\Documents and Settings\Bradley\Local Settings\Temporary Internet Files\Content.IE5\PNBCU0XJ\35[1].htm Suspicious: Exploit.HTML.CodeBaseExec skipped

C:\System Volume Information\_restore{F35AD163-EF2E-4F4F-8B9F-93E0D7336EF4}\RP15\A0004440.exe Infected: not-a-virus:AdWare.Win32.MediaTickets.w skipped

C:\System Volume Information\_restore{F35AD163-EF2E-4F4F-8B9F-93E0D7336EF4}\RP16\A0004689.exe Infected: not-a-virus:Downloader.Win32.Agent.h skipped

C:\System Volume Information\_restore{F35AD163-EF2E-4F4F-8B9F-93E0D7336EF4}\RP18\A0004723.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.cd skipped

Scan process completed.


HJT Log –>

Logfile of HijackThis v1.99.1
Scan saved at 20:24:15, on 24/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MyStuff\Software\HijackThis\Banana.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\MyStuff\Software\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {DDC88A13-852C-4797-B764-7FE10712CBAE} - C:\WINDOWS\system32\jkklk.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

thanks for all of your help so far i really do appreciate it.

ps what made you think of changing the name of the HJT executable?

Cheers B.Cooper ;)

what made you think of changing the name of the HJT executable?


Theres a new version of 'vundo' going around, which prevent's HijackThis from working properly unless it's renamed (notice that your log doesn't show any entries starting with O2 or O20 untill HijackThis is renamed). It was just a guess that renaming it would get the uninstall log to work aswell, but the lack of O2's or O20's in your log indicated that you might have vundo. ;)

Speaking of which:

Please download vundofix.exeto your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • In case it says that nothing was been found, Right click the list box (white box) in the main VundoFix window.
  • Select “Add More Files?” from the menu that comes up. This will open a new VundoFix window.
  • In the Window: copy and paste this in the first field: C:\WINDOWS\system32\jkklk.dll
  • Copy and paste this in the second field: C:\WINDOWS\system32\klkkj.*
  • Click the “Add Files” button.
  • Click the "Close Window" button.
  • Click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Vundo ay… sounds good to me! –>


VundoFix V5.1.5

Running as SYSTEM
from c:\windows\system32\VundoFix.exe

Checking Java version…

Java version is 1.5.0.3

Scan started at 22:32:04 24/07/2006

Listing files found while scanning….

C:\windows\system32\jkklk.dll
C:\windows\system32\klkkj.ini
C:\windows\system32\klkkj.bak1
C:\windows\system32\klkkj.bak2
C:\windows\system32\klkkj.ini2
C:\windows\system32\klkkj.tmp

Beginning removal…

The process smss.exe was successfully stopped

The process winlogon.exe was successfully stopped

The process explorer.exe was successfully stopped

The process iexplore.exe was successfully stopped

The process rundll32.exe was successfully stopped

Attempting to delete C:\windows\system32\jkklk.dll
C:\windows\system32\jkklk.dll Has been deleted!

Attempting to delete C:\windows\system32\klkkj.ini
C:\windows\system32\klkkj.ini Has been deleted!

Attempting to delete C:\windows\system32\klkkj.bak1
C:\windows\system32\klkkj.bak1 Has been deleted!

Attempting to delete C:\windows\system32\klkkj.bak2
C:\windows\system32\klkkj.bak2 Has been deleted!

Attempting to delete C:\windows\system32\klkkj.ini2
C:\windows\system32\klkkj.ini2 Has been deleted!

Attempting to delete C:\windows\system32\klkkj.tmp
C:\windows\system32\klkkj.tmp Has been deleted!

Performing Repairs to the registry.
Done!


HJT Log–>

Logfile of HijackThis v1.99.1
Scan saved at 22:40:28, on 24/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\MyStuff\Software\HijackThis\Banana.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\MyStuff\Software\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {DDC88A13-852C-4797-B764-7FE10712CBAE} - C:\WINDOWS\system32\jkklk.dll (file missing)
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

Thanks for the quick reply, muchly appreciated!

B.Cooper

Where abouts are you?? UK??
Yup.

Huzzahs! Vundo seems to have gone without a fuss :)

1)

Run HijackThis, put a check-mark next to these entrys:

O2 - BHO: (no name) - {DDC88A13-852C-4797-B764-7FE10712CBAE} - C:\WINDOWS\system32\jkklk.dll (file missing)

O20 - Winlogon Notify: winccf32 - winccf32.dll (file missing)


And click the 'fix' button.

———-

2) Show hidden files

Please set your computer to show hidden files, by doing this:
  • Click Start.
  • Open "My Computer"
  • Select the "Tools" menu and click "Folder Options"
  • Select the "View" Tab
  • Under the "Hidden files and folders" heading select "Show hidden files and folders"
  • Uncheck the "Hide protected operating system files (recommended)" option
  • Click "Yes" to confirm
  • Click "OK".
———-

3) Reboot into safe-mode

Please reboot into safe-mode by restarting your computer, and continually poking the F8 button whilst it is loading up.

In the menu that appears, use the arrows on your keyboard to select "safe mode" and press enter.

———-

4) Delete files and folders

Please delete any of the following files, if they still exist:


C:\Documents and Settings\Bradley\Local Settings\Temp\mst6C.tmp

C:\WINDOWS\system32\1024\ld78D0.tmp

C:\windows\system32z\winccf32.dll

———-

reboot into normal mode, and run ewido.

Update it, and then select the "Scanner" icon at the top of the screen, then select the "Settings" tab.

Under "Reports", select "Automatically generate report after every scan" and un-Select "Only if threats were found"

Please do a full-system scan with ewido, and allow it to fix anything that it finds.

after the scan is complete, click on the 'reports' button, and copy/paste the report as a reply to this thread, along with a new HijackThis log (or a banana log, i suppose :D)

Also, how is your computer behaving now? is your anti-virus software still giving you warnings?
Ewido Log–>

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 17:44:07 27/07/2006

+ Scan result:



HKU\S-1-5-21-1214440339-1659004503-682003330-1003\Software\Classes\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1214440339-1659004503-682003330-1003_Classes\CLSID\{7916f057-223f-4612-ac84-e882cbe043d4} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Bradley\Local Settings\Temp\win6E.tmp.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Bradley\Cookies\bradley@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@newlinecinema.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.17:C:\Documents and Settings\Bradley\Application Data\Mozilla\Firefox\Profiles\rnvcvavp.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Bradley\Cookies\bradley@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Bradley\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\RECYCLER\S-1-5-21-1214440339-1659004503-682003330-1003\Dc9.tmp -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).


::Report end

Banana Log :D –>

Logfile of HijackThis v1.99.1
Scan saved at 17:46:13, on 27/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Rundll32.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MyStuff\Software\HijackThis\Banana.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\MyStuff\Software\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\MyStuff\Software\AVG\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\MyStuff\Software\AVG\avgupsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\MyStuff\Software\Ewdio\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

Umm yeah it hasent given me a warning in a while, although i havent been home much recently to use the computer! Ewido seemed to pick up quite a few things :blink: !! also i looked but i dont have a system32z

C:\windows\system32z\winccf32.dll

and i couldent find

C:\WINDOWS\system32\1024\ld78D0.tmp

but i did delete

C:\Documents and Settings\Bradley\Local Settings\Temp\mst6C.tmp

there was another file with the same name but it wasent a tmp. file so i left it alone.. is it ok??

how are you anyhow?? thankyou once again for all of the help you have given me, i cant tell you how grateful i am, its great that there are people willing to share what they know to help other people with their problems, so once again thankyou!!

Many thanks

B.Cooper
no worries, and thank you :D

Most of the things found by ewido were tracking cookies, which aren't really much to worry about, but there was a trojan in there.

C:\windows\system32z\winccf32.dll


:oops: That was a typo (whoops!).

could you try and delete C:\windows\system32\winccf32.dll.

but i did delete

C:\Documents and Settings\Bradley\Local Settings\Temp\mst6C.tmp

there was another file with the same name but it wasent a tmp. file so i left it alone.. is it ok??


Where was the file? and was it mst6C.exe?

Your log looks clean now, but i'd like to check that none of the trojans have installed any more viruses.

Could you do one more online kaspersky scan and post the log up please (instructions in post 4), and then we can probably move on to the final cleanup :)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI