MyLog File:
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe
C:\WINDOWS\bWlrZQ\command.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\hijackthis\HijackThis.exe
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [tSdURg2] "C:\WINDOWS\System32\fhsxc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE
O4 - HKCU\..\Run: [Trpp] "C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe" -vt ndrv
O18 - Filter: text/html - {F8D76886-FA88-4DF6-8FBD-C02CF8C91C94} - C:\WINDOWS\System32\ubbv.dll
O20 - AppInit_DLLs: wowexec.dll
O20 - Winlogon Notify: Uninstall - C:\WINDOWS\system32\k0js0a17ed.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bWlrZQ\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Please download
Look2Me-Destroyer.exe to your desktop.
Close all windows before continuing. Double-click Look2Me-Destroyer.exe to run it. Put a check next to Run this program as a task . You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds . Click OK When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal. Once it's done scanning, click the Remove L2M button . You will receive a Done Scanning message , click OK . When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer , click OK . Your computer will then shutdown. Turn your computer back on. Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log . If you receive a message from your firewall about this program accessing the internet please allow it.
If you receive a
runtime error '339' . please download MSWINSCK.OCX from the link below and place it in your
C:\Windows\System32 . Directory
MSWINSCK.OCX
Please post the
ENTIRE HijackThis! log.
The last one was missing the "header" info.
There will be other things to remove.
thank you very much Micah
This is my log file after i used Look2me Destroyer, i am still having popup problems also. Any help is much appreciated, thanks
Logfile of HijackThis v1.99.1
Scan saved at 5:29:43 PM, on 8/29/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\bWlrZQ\command.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}\Update.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [tSdURg2] "C:\WINDOWS\System32\fhsxc.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE
O4 - HKCU\..\Run: [Trpp] "C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe" -vt ndrv
O18 - Filter: text/html - {F8D76886-FA88-4DF6-8FBD-C02CF8C91C94} - C:\WINDOWS\System32\ubbv.dll
O20 - AppInit_DLLs: wowexec.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bWlrZQ\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "
Do a systen scan only ".
Then "check" the box to the left of these item(s):
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKLM\..\Run: [tSdURg2] "C:\WINDOWS\System32\fhsxc.exe"
O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE
O4 - HKCU\..\Run: [Trpp] "C:\DOCUME~1\mike\APPLIC~1\PPATCH~2\spool32.exe" -vt ndrv
O18 - Filter: text/html - {F8D76886-FA88-4DF6-8FBD-C02CF8C91C94} - C:\WINDOWS\System32\ubbv.dll
O20 - AppInit_DLLs: wowexec.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\bWlrZQ\command.exe
Then click "
Fix checked " and close Hijack This!.
Now, please go to:
Start –>
Run
In the box type in
services.msc then hit
< Enter > (or click
OK )
In the
Name column look for:
Command Service
< Double-click > it.
In the dialogue box that pops up, check in the
Path to executable box.
It should say:
C:\WINDOWS\bWlrZQ\command.exe
That's how to be sure you have the right one.
Now, click
Stop to stop that rogue process.
In the
Startup type box, change it to
Disabled .
Click
Apply then
OK
Close the services.msc window.
Reboot in
"safe" mode .
Delete all of the following
noted (in red) file(s)/
FOLDER(s) you can find:
c:\documents and settings\mike\application data\
ppatch~2 <—
FOLDER
c:\windows\
bwlrzq <—
FOLDER
c:\windows\
racle~1 <—
FOLDER
c:\windows\system32\
fhsxc.exe <— file
c:\windows\system32\
ubbv.dll <— file
c:\windows\system32\
wowexec.dll <— file
(
DO NOT DELETE WOWEXEC.EXE !!! )
Some malware files may be "hidden".
Be sure to
show hidden files when looking for these file(s) and/or folder(s).
Reboot in normal mode and "copy/paste" a new HijackThis! log file
into this thread .
Please use the
[external image: Posted Image] button, and do not start a new thread.
There is at least one other item left to take care of, even if your endeavors on these items are successful.
Here is my new HiJack Log File:
Logfile of HijackThis v1.99.1
Scan saved at 6:27:47 PM, on 8/29/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}\Update.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\syshost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\srshost.exe
C:\Program Files\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [Microsoft Windows System] syshost.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunServices: [Microsoft Windows System] syshost.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE
O4 - HKCU\..\Run: [srshost.exe] C:\WINDOWS\system32\srshost.exe
O4 - Global Startup: Wincbr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "
Do a systen scan only ".
Then "check" the box to the left of these item(s):
O4 - HKLM\..\Run: [Microsoft Windows System] syshost.exe
O4 - HKLM\..\RunServices: [Microsoft Windows System] syshost.exe
O4 - HKCU\..\Run: [Hxawh] C:\WINDOWS\RACLE~1\WACLT~1.EXE
O4 - HKCU\..\Run: [srshost.exe] C:\WINDOWS\system32\srshost.exe
O4 - Global Startup: Wincbr.exe
Then click "
Fix checked " and close Hijack This!.
Reboot in
"safe" mode .
Delete all of the following
noted (in red) file(s)/
FOLDER(s) you can find:
c:\windows\
racle~1 <—
FOLDER
c:\windows\system32\
srshost.exe <— file
c:\windows\system32\
syshost.exe <— file
wincbr.exe <— file
Some malware files may be "hidden".
Be sure to
show hidden files when looking for these file(s) and/or folder(s).
Reboot in normal mode and "copy/paste" a new HijackThis! log file
into this thread .
You need a firewall -
ASAP !!!
Free ones are located here:
Securing Your PC After An Attack
Or find one of your own choosing.
While your there looking at links, think about an antivirus as well.
You'll need one of those as well.
DON'T INSTALL ANY ANTIVIRUS JUST YET!
Thank you for all your help!
Logfile of HijackThis v1.99.1
Scan saved at 7:29:02 PM, on 8/29/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\{3829BA0F-015E-1033-0303-000723980001}\Update.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Unless something new shows up, only 1 "bad boy" left.
Please download/unzip this:
Registry Search 2.0 by Bobbi Flekman © 2005
on
regsearch.exe , and search for this:
{3829BA0F-015E-1033-0303-000723980001}
[external image: Posted Image] Make sure ALL the boxes are checked under "Search".
It may take a while to run, so be patient. When finished, the search results will appear in your text editor,
Paste the contents of the search results into your next post.
REGEDIT4
; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.1.0
; Results at 8/29/2006 7:57:05 PM for strings:
; '{3829ba0f-015e-1033-0303-000723980001}'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS
[HKEY_USERS\S-1-5-21-2025429265-436374069-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"{3829BA0F-015E-1033-0303-000723980001}"="\"C:\\Program Files\\Common Files\\{3829BA0F-015E-1033-0303-000723980001}\\Update.exe\" mc-110-12-0000103"
; End Of The Log…
Copy and paste the contents of the quote box below into notepad.
Save it as file name: "
fixme.reg " (not including the quotes). Save as file type: *All files* and save it on your Desktop.
REGEDIT4
[HKEY_USERS\S-1-5-21-2025429265-436374069-1957994488-1003\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"{3829BA0F-015E-1033-0303-000723980001}"=-
Then, locate
fixme.reg on your desktop and it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer '
Yes ' and wait for a message to appear similar to "Merged Successfully".
Reboot.
Delete this
FOLDER :
C:\Program Files\Common Files\
{3829BA0F-015E-1033-0303-000723980001}
Reboot and post a new HijackThis! log.
Unless something new appears, this should take care of things.
If the log looks good, I'd like for you to try at least one of these online virus scans:
Trend-Micro Housecall
Put on '
Autoclean' and delete what it can't clean .
Etrust Security Advisor
Choose '
Cure' whatever is found, then delete if unsuccessful .
Bitdefender
If they find something they can't fix, or delete, let me know.
As soon as all the "bugs" are fixed, choose a firewall and an antivirus.
Some free ones can be found here:
Securing Your PC After An Attack
Without a firewall/antivirus, you're an infection just waiting to happen….
Thanks again,
Logfile of HijackThis v1.99.1
Scan saved at 8:33:48 PM, on 8/29/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\devldr32.exe
C:\Documents and Settings\mike\Local Settings\Temp\Temporary Directory 8 for hijackthis.zip\HijackThis.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Looks good.
Please follow up on the suggestions I made in my last post.
Let me know if you have any problems.
Thank you for choosing TomCoyote for your malware removal solutions.
M68
Securing Your PC After An Attack