This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My HijackThis Log..Need Help Please.

35 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey Gary, I had done the thing with system restore, turn it off, apply, etc then reboot and turn it back on… So I did follow your steps..and after I was done with all that you said in that post, I ran online kaspersky again and posted the log…so I dont know how it still found files in system restore…thats what confused me… Ok and results about that particular file are as follows: Scan taken on 19 Feb 2007 19:37:09 (GMT) AntiVir Found TR/BHO.G.27 ArcaVir Found Trojan.Bho.G Avast Found nothing AVG Antivirus Found Generic3.AWS BitDefender Found nothing ClamAV Found nothing Dr.Web Found Trojan.Virtumod F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan.Win32.BHO.g Fortinet Found nothing Kaspersky Anti-Virus Found Trojan.Win32.BHO.g NOD32 Found nothing Norman Virus Control Found nothing VirusBuster Found Trojan.BHO.AM VBA32 Found nothing That was from one of them…I ran the file in both the ones you posted…here is the other one….
here is from the other o ne… Complete scanning result of "cpliebaf.dll", received in VirusTotal at 02.19.2007, 20:40:41 (CET). Antivirus Version Update Result AntiVir 7.3.1.37 02.19.2007 TR/BHO.G.27 Authentium 4.93.8 02.19.2007 no virus found Avast 4.7.936.0 02.19.2007 no virus found AVG 386 02.19.2007 Generic3.AWS BitDefender 7.2 02.19.2007 no virus found CAT-QuickHeal 9.00 02.19.2007 no virus found ClamAV devel-20060426 02.19.2007 no virus found DrWeb 4.33 02.19.2007 Trojan.Virtumod eSafe 7.0.14.0 02.19.2007 no virus found eTrust-Vet 30.4.3412 02.19.2007 Win32/Darksma.W Ewido 4.0 02.19.2007 no virus found FileAdvisor 1 02.19.2007 no virus found Fortinet 2.85.0.0 02.19.2007 suspicious F-Prot 4.2.1.29 02.16.2007 no virus found F-Secure 6.70.13030.0 02.19.2007 Trojan.Win32.BHO.g Ikarus T3.1.0.31 02.19.2007 Trojan.Win32.BHO.g Kaspersky 4.0.2.24 02.19.2007 Trojan.Win32.BHO.g McAfee 4966 02.19.2007 no virus found Microsoft 1.2204 02.19.2007 no virus found NOD32v2 2070 02.19.2007 no virus found Norman 5.80.02 02.19.2007 no virus found Panda 9.0.0.4 02.18.2007 Application/VSToolbar Prevx1 V2 02.19.2007 no virus found Sophos 4.14.0 02.19.2007 no virus found Sunbelt 2.2.907.0 02.17.2007 VIPRE.Suspicious Symantec 10 02.19.2007 no virus found TheHacker 6.1.6.060 02.19.2007 Trojan/BHO.g UNA 1.83 02.19.2007 Trojan.Win32.BHO.B0D9
Hi Parth,

Seems we missed something and it's re-infecting you.

OK lets look a little deeper.

First delete the file C:\WINDOWS\system32\cpliebaf.dll

Let me know if any problem doing it.

Download GMER and unzip it to your Desktop. (It will create a folder GMER)

Alternate Download Site
  • Disconnect from the Internet, and close all running programmes.
  • There is a small chance this programme may crash your computer, so save any work you have open.
  • Open the GMER folder, and double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at programme start about rootkit activity and asks if you want to run a scan ….. click OK.
  • If no warning:
    • Click Rootkit tab.
    • Ensure that All the boxes to the right of the program are checked except Show All.
    • Click Scan.
  • Once scan is finished click Copy.
    • Click Start > Run then type Notepad.exe then click OK.
    • This will open a Notepad file.
    • Hit Ctrl+V to paste log into it.
    • Save the log to your Desktop.
  • Reconnect to internet and post the log please along with a new HJT log.
Ok I deleted the file..
here is the rootkit log..

GMER 1.0.12.12027 - http://www.gmer.net
Rootkit scan 2007-02-20 01:03:06
Windows 5.1.2600 Service Pack 2


—- Devices - GMER 1.0.12 —-

Device \FileSystem\Udfs \UdfsCdRom IRP_MJ_FILE_SYSTEM_CONTROL [ED6CAA05] tfsnifs.sys
Device \FileSystem\Udfs \UdfsDisk IRP_MJ_FILE_SYSTEM_CONTROL [ED6CAA05] tfsnifs.sys
Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE EC1B0C8A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE EC1AD7C8
Device \FileSystem\Fastfat \Fat IRP_MJ_READ EC1A960A
Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE EC1A9AED
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION EC1B4958
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION EC1B7821
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA EC1C038A
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA EC1BFD49
Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS EC1B9BBE
Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION EC1BA331
Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION EC1C84F4
Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL EC1B0B37
Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL EC1AC948
Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL EC1B646B
Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN EC1C779D
Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL EC1C6C4A
Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP EC1AD2FD
Device \FileSystem\Fastfat \Fat IRP_MJ_PNP EC1C71DB
Device \FileSystem\Fastfat \Fat FastIoCheckIfPossible EC1C21F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [ED6CA701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [ED6CA701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [ED6CA701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [ED6CA701] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [ED6CA701] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [ED6CA89D] tfsnifs.sys

—- EOF - GMER 1.0.12 —-
And here is the new HJT log


Logfile of HijackThis v1.99.1
Scan saved at 1:06:34 AM, on 2/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\eHome\EHTray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Backup\MyIE\MyIE.exe
C:\hijackthis\FredFlinstone.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/ractrl.cab?lmi=100
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: LMIinit - C:\WINDOWS\SYSTEM32\LMIinit.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hi Parth,

OK, no hidden Rootkits. The tfsnifs.sys is a driver concerned with Drive Letter Access, it seems to be related to your DVD/CD drive and appears to be standard on most Dell and some Toshiba computers.

HJT log still looks clean (which is good).

I'd like you to do the following (strictly in the order given please).

1. Boot into Safe Mode and run a scan with AVG Anti-Spyware (as detailed in my earlier post).

2. Clear your Temp files using ATF Cleaner.

3. Reboot into Normal Mode.

4.
  • Turn off System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Check Turn off System Restore.
    • Click Apply, and then click OK.
  • Reboot. (This is essential).
  • Turn ON System Restore.
    • On the Desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • UN-Check *Turn off System Restore*.
    • Click Apply, and then click OK.

5. Run a new Kaspersky scan please.

Now can you send me the Kaspersky log, the AVG log, a new HJT log please.

Can you also send me an Uninstall List.

Creating an Uninstall List
  • Open HJT, and click on Config, followed by Misc Tools.
  • Click on Open Uninstall Manager, and then click on Save List.
  • This will create a file uninstall_list.txt and prompt you to save it to your HJT folder.
  • Save it please.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI