This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] start page virus

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi..
Below is my Hijjack this log file. Please let me know if there is a home page virus and how do i remove it

Logfile of HijackThis v1.99.1
Scan saved at 11:49:41, on 25/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscript.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\Rar$EX00.250\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sujin.com.np/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Sujin.com.np
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wscript.exe C:\WINDOWS\system32\VirusRemoval.vbs
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Messenger\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IECatcher Class - {569E7719-1A11-415E-9206-AC1860FB8BFF} - C:\Program Files\InstantGet\IGCatcher.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: InstantGet Bar - {98C92840-EB1C-40bd-B6A5-395EC9CD6510} - C:\Program Files\InstantGet\IGIEBar.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Messenger\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O8 - Extra context menu item: &Download with InstantGet - res://C:\Program Files\InstantGet\IGCatcher.dll/IGLink.htm
O8 - Extra context menu item: Download &all with InstantGet - res://C:\Program Files\InstantGet\IGCatcher.dll/IGAll.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Run InstantGet - {6DDFE91C-A45C-4812-8F57-098932C9D88D} - C:\Program Files\InstantGet\InstantGet.exe
O9 - Extra 'Tools' menuitem: &InstantGet - {6DDFE91C-A45C-4812-8F57-098932C9D88D} - C:\Program Files\InstantGet\InstantGet.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{75B5F407-F8EA-42F3-B0BF-0ABABEDD9907}: NameServer = 208.110.16.12,208.110.16.13,208.110.16.14
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe

regards
MSS
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Sujin.com is not your homepage is it? It looks like a company that sells toilets and bidets. There was also a notice from the company about being redirected to its homepage, which I dont believe is their fault.
Hi Scotty ….Sending you the uninstall list as requested. As for your question if Sujin.com was my home page, the answer is no. Its not my home page and i have never heard about it before. Hope to hear from you soon. regards MSS ACDSee 5.0 Standard Adobe Acrobat 5.0 Adobe Flash Player 9 ActiveX Adobe PageMaker 7.0 Adobe Photoshop 7.0 Ahead Nero - Burning Rom AVG Anti-Spyware 7.5 CCleaner (remove only) Free Video to iPod Converter version 2.1 Google Talk (remove only) HijackThis 1.99.1 InstantGet LiveReg (Symantec Corporation) LiveUpdate 1.7 (Symantec Corporation) LiveUpdate 1.80 (Symantec Corporation) Microsoft Office Professional Edition 2003 Microsoft Text-to-Speech Engine 4.0 (English) NOD32 antivirus system NOD32 FiX v2.1 Norton AntiVirus Corporate Edition Norton Ghost pdfFactory Pro Picasa 2 QuickTime Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Spybot - Search & Destroy 1.4 SpywareBlaster v3.5.1 Super Fast Shutdown 1.0 SuperCleaner Uninstall LAC VIET mtd2002-EVA Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Winamp3 (remove only) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver WinZip Yahoo! Extras Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar
Hi

You are operating your computer with multiple Anti Virus programs running in memory at once:
NOD32 and Norton

Anti-virus programs take up an enormous amount of your computer's resources when they are actively scanning your computer. Having two anti-virus programs running at the same time can cause your computer to run very slow, become unstable and even, in rare cases, crash.

If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

There are basically two types of these programs:
On-Access and On-Demand

On-Access Scanners
As the name implies, it runs in the background all the time the PC is turned on and running. The main function of an on-access scanner is to monitor activity on your machine.

On-Demand Scanners
As the name implies, are scanners that only run when you ask them to.
Such as:
Online Scans and scanners that run on your machine but are not actively scanning your machine.

Please disable one or the other so they do not conflict.


Go to http://www.virustotal.com/en/indexf.html
Copy the following line into the white textbox:
C:\WINDOWS\system32\VirusRemoval.vbs
Click Send.
Please post the results of this scan to this thread.
Hi…..here is the scan result as requested Antivirus Version Last Update Result AhnLab-V3 2007.10.25.0 2007.10.25 - AntiVir 7.6.0.27 2007.10.25 HEUR/Exploit.HTML Authentium 4.93.8 2007.10.24 - Avast 4.7.1074.0 2007.10.25 - AVG 7.5.0.488 2007.10.25 - BitDefender 7.2 2007.10.25 - CAT-QuickHeal 9.00 2007.10.25 - ClamAV 0.91.2 2007.10.25 - DrWeb 4.44.0.09170 2007.10.25 modification of VBS.Generic.553 eSafe 7.0.15.0 2007.10.22 VBS.Vote.b1 eTrust-Vet 31.2.5241 2007.10.25 - Ewido 4.0 2007.10.25 - FileAdvisor 1 2007.10.25 - Fortinet 3.11.0.0 2007.10.19 - F-Prot 4.3.2.48 2007.10.25 - F-Secure 6.70.13030.0 2007.10.25 - Ikarus T3.1.1.12 2007.10.25 - Kaspersky 7.0.0.125 2007.10.25 - McAfee 5149 2007.10.25 - Microsoft 1.2908 2007.10.25 - NOD32v2 2617 2007.10.25 VBS/Small.NAA Norman 5.80.02 2007.10.25 - Panda 9.0.0.4 2007.10.25 - Prevx1 V2 2007.10.25 - Rising 19.46.31.00 2007.10.25 - Sophos 4.22.0 2007.10.25 - Sunbelt 2.2.907.0 2007.10.24 - Symantec 10 2007.10.25 - TheHacker 6.2.9.107 2007.10.25 - VBA32 3.12.2.4 2007.10.24 - VirusBuster 4.3.26:9 2007.10.25 - Additional information File size: 11310 bytes MD5: 52498852bd87c5acccd4b061e6f1a7e0 SHA1: 9074ee95a62a32ea2df0153580116e8e6154f45c packers: Unicode packers: Unicode
Hi

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back in your next reply.
Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Hi

My SDfix log:

SDFix: Version 1.112

Run by [removed] on Sat 10/27/2007 at 08:19 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

No Trojan Files Found




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

Remaining Files:
—————


Files with Hidden Attributes:


Finished!

COMBOFIX LOG:

ComboFix 07-10-27.4 - OEMUser 2007-10-27 20:29:01.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.297 [GMT -7:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\start.exe

.
((((((((((((((((((((((((( Files Created from 2007-09-28 to 2007-10-28 )))))))))))))))))))))))))))))))
.

2007-10-28 06:18 d–hs—- C:\Recycled
2007-10-27 20:28 51,200 –a—— C:\WINDOWS\NirCmd.exe
2007-10-27 20:18 d——– C:\WINDOWS\ERUNT
2007-10-27 19:39 99,965 –a—— C:\WINDOWS\UninstallFirefox.exe
2007-10-27 19:39 2,654 –a—— C:\WINDOWS\mozver.dat
2007-10-27 19:39 0 –a—— C:\WINDOWS\nsreg.dat
2007-10-27 19:08 d–h—– C:\WINDOWS\SYSTEM32\GroupPolicy
2007-10-27 17:52 11,310 -rahs—- C:\WINDOWS\SYSTEM32\VirusRemoval.vbs
2007-10-27 17:51 d—s—- C:\Documents and Settings\OEMUser\UserData
2007-10-27 17:00 d——– C:\Program Files\Super Fast Shutdown
2007-10-27 17:00 d——– C:\Program Files\Microsoft ActiveSync
2007-10-27 16:59 d——– C:\WINDOWS\ShellNew
2007-10-27 16:38 d——– C:\Documents and Settings\OEMUser\Application Data\Yahoo! Messenger
2007-10-27 16:13 d——– C:\Program Files\Symantec
2007-10-27 16:13 d——– C:\Program Files\NavNT
2007-10-27 16:13 d——– C:\Program Files\Common Files\Symantec Shared
2007-10-27 16:13 d——– C:\Documents and Settings\All Users\Application Data\Symantec
2007-10-27 16:13 57,696 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\SYMEVENT.SYS
2007-10-27 16:13 36,864 –a—— C:\WINDOWS\SYSTEM32\S32EVNT1.DLL
2007-10-27 16:13 4,032 –a—— C:\WINDOWS\SYSTEM32\SYMEVNT1.DLL
2007-10-27 16:12 d——– C:\Program Files\Common Files\InstallShield
2007-10-27 16:12 d——– C:\Documents and Settings\OEMUser\WINDOWS
2007-10-27 16:09 26,496 –a—— C:\WINDOWS\SYSTEM32\dllcache\usbstor.sys
2007-10-27 16:05 d——– C:\Program Files\Yahoo!
2007-10-27 15:48 d—s—- C:\WINDOWS\SYSTEM32\Microsoft
2007-10-27 15:33 d——– C:\Program Files\microsoft frontpage
2007-10-27 15:32 152,576 –a—— C:\WINDOWS\SYSTEM32\migicons.exe
2007-10-27 15:31 d–hs—- C:\Documents and Settings\All Users\DRM
2007-10-27 15:28 3,072 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\audstub.sys
2007-10-27 15:27 57,472 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\redbook.sys
2007-10-27 15:27 44,672 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\UAGP35.SYS
2007-10-27 15:27 27,165 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\fetnd5.sys
2007-10-27 15:26 74,240 –a—— C:\WINDOWS\SYSTEM32\usbui.dll
2007-10-27 15:25 dr——- C:\Documents and Settings\All Users\Documents
2007-10-27 15:25 d——– C:\Documents and Settings
2007-10-27 15:21 d–hs—- C:\undo
2007-10-27 15:10 d——– C:\WINDOWS\MDMUPGLG
2007-10-27 14:56 d——– C:\WINDOWS\SYSTEM\CatRoot
2007-10-27 14:56 d——– C:\Program Files\DirectX
2007-10-27 14:55 d—s—- C:\WINDOWS\Downloaded Program Files
2007-10-27 14:55 172,064 -r-h—– C:\WINDOWS\HWINFO.DAT
2007-10-27 14:54 d——– C:\WINDOWS\All Users
2007-10-27 14:06 d–h—– C:\WINDOWS\SYSBCKUP
2007-10-27 14:06 d–h—– C:\WINDOWS\spool
2007-10-27 14:06 d–h—– C:\WINDOWS\APPLOG
2007-10-27 08:19 17,408 –a—— C:\WINDOWS\SYSTEM32\dllcache\ocmsn.dll
2007-10-27 08:19 15,360 –a—— C:\WINDOWS\SYSTEM32\dllcache\msgrocm.dll
2007-10-27 08:18 2,897,920 –a—— C:\WINDOWS\SYSTEM32\dllcache\xpsp2res.dll
2007-10-27 08:18 51,456 –a—— C:\WINDOWS\SYSTEM32\dllcache\vga256.dll
2007-10-27 08:18 33,792 –a—— C:\WINDOWS\SYSTEM32\dllcache\tabletoc.dll
2007-10-27 08:18 18,176 –a—— C:\WINDOWS\SYSTEM32\dllcache\vga64k.dll
2007-10-27 08:18 16,896 –a—— C:\WINDOWS\SYSTEM32\dllcache\medctroc.dll
2007-10-27 08:12 1,852,416 –a—— C:\WINDOWS\SYSTEM32\dllcache\acgenral.dll
2007-10-27 08:12 616,960 –a—— C:\WINDOWS\SYSTEM32\dllcache\advapi32.dll
2007-10-27 08:12 194,048 –a—— C:\WINDOWS\SYSTEM32\dllcache\activeds.dll
2007-10-27 08:12 143,360 –a—— C:\WINDOWS\SYSTEM32\dllcache\adsldpc.dll
2007-10-27 08:12 126,976 –a—— C:\WINDOWS\SYSTEM32\dllcache\apphelp.dll
2007-10-27 08:12 99,840 –a—— C:\WINDOWS\SYSTEM32\dllcache\advpack.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-27 21:55 266 –sh–w C:\Program Files\desktop.ini
2007-10-27 21:55 11,079 —h–w C:\Program Files\folder.htt
2007-10-27 21:01 ——— d—–w C:\Program Files\PLUS!
2007-10-27 21:01 ——— d—–w C:\Program Files\CHAT
2007-10-27 21:01 ——— d—–r C:\Program Files\Accessories
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\ypager.exe" [2004-06-07 14:44]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 01:06]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SchedulingAgent"=mstinit.exe /firstlogon


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bdc59d68-84e1-11dc-b056-00012e19426d}]
AutoRun\command - wscript.exe VirusRemoval.vbs
open\Command - wscript.exe VirusRemoval.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{da8a8806-84fe-11dc-b062-00012e19426d}]
AutoRun\command - wscript.exe VirusRemoval.vbs
open\Command - wscript.exe VirusRemoval.vbs

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"1999-04-24 05:22:00 C:\WINDOWS\Tasks\Tune-up Application Start.job"
"2007-10-27 22:49:02 C:\WINDOWS\Tasks\Uninstall Expiration Reminder.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-27 20:29:50
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-10-27 20:30:20
.
— E O F —

Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 11:06:37 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\OEMUser\LOCALS~1\Temp\Rar$EX00.687\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Win32 Classes -
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O17 - HKLM\System\CS1\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O17 - HKLM\System\CS2\Services\Tcpip\..\{4E23F82E-96EA-4113-B15B-3F20B2722CA4}: NameServer = 208.110.16.14,208.110.16.13
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe



Regards
MSS
Hi

Download Flash_Disinfector from herea nd save it to your desktop.
Doubleclick on Flash_Disinfector.exe to run it and follow the prompts.
Wait until it has finished scanning and then exit the program.
The utility may ask you to insert your flash drive and/or other removable drives. This may include your mobile phone.
Please do so and allow the utility to clean up those drives as well.



Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\WINDOWS\SYSTEM32\VirusRemoval.vbs

DirLook::
C:\WINDOWS\SYSTEM32\GroupPolicy 
C:\undo

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post with a new HijackThis log.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI