Hey,
There havent been much problems, until a few days back when i ran a check on AVG Anti-Spyware just to be sure. Turned out that there were Trojons and backdoors, and I cleaned all these infected files based on the recommended actions.
================================================================================
Upon startup,
A black window ""C:\WINNT\system32\cmd.exe" will run, with some texts in it. After a while, it will close by itself.
After which there will be 2 black windows with title "C:\WINNT\system32\svchost.exe". There are no texts in the box. Just a black background. Nothing happens when I close the pop-up.
EDIT:
I realised that everytime that i run a new program on my computer, the black box "C:\WINNT\system32\svchost.exe" will pop-up.
After a while of using, there will also be this pop-up with title "Dialuppass.exe - Unable to Locate DLL"
The content written inside is,
"The dyanamic link library SOFT2CN(some weird symbols) could not be found in the specified path
C:\WINNT;,;C:\WINNT\system32;C:\WINNT\system;C:\WINNT;C:\WINNT\system32;C:\WINNT;C:\WINNT\System32\Wbem
================================================================================
In AVG Anti-Spyware, there's a tab "Analysis", "Autostart". In which, there is 3 applications "ctfmen" with an icon of a penguin. I have listed them below.
Application: ctfmen
Location: Registry\HKLM\Run
Path: C:\WINNT\ctfmen.exe
Application: C:\WINNT\ctfmen.exe
Location: WIN.INI\WINDOWS\LOAD
Path: C:\WINNT\ctfmen.exe
Applicatoin: C:\WINNT\ctfmen.exe
Location :WIN.INI\WINDOWS\RUN
Path: C:\WINNT\ctfmen.exe
I googled the term "ctfmen", and it is being labelled as a trojan_backdoor on this website,
"
http://www.processlib.net/files/ctfmen.exe.html"
"
http://www.liutilities.com/products/campai…hatsrunning/rb/" offers to run scans to clear any such exe problem.
Is there anyway to differentiate genuine sites which offer real help and malicious sites which trick you to download even more trojans?
================================================================================
In my external Hard Disc, E Drive, there is a hidden icon, with the same picture of the penguin.
I right-clicked to check the properties and it is an application. After which I scanned it with AVG Anti-Spyware and nothing turned up. However when I double-clicked on the icon, my whole screen turns blue. After which it will auto-restart.
I do not remember downloading or installing any files with ctfmen, or with the penguin icon.
I hope you can help me out with regards to this.
================================================================================
I ran AVG Anti-Spyware. This is the log.
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 8:11:05 AM 11/9/2007
+ Scan result:
[576] C:\WINNT\system32\FireFoxUpdater.exe -> Downloader.Small.dwp : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.15:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.16:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.33:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.34:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.35:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.36:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.37:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.40:C:\Documents and Settings\Ak1\Application Data\Mozilla\Firefox\Profiles\txghm8jz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
::Report end
================================================================================
Log of HijaskThis
Logfile of HijackThis v1.99.1
Scan saved at 8:12:22 AM, on 11/9/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\GSICON.EXE
C:\WINNT\system32\dslagent.exe
C:\PROGRA~1\Java\JRE16~1.0_0\bin\jusched.exe
C:\program files\internet explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.nb4f.com.cn
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.nb4f.com.cn
F3 - REG:win.ini: load=C:\WINNT\ctfmen.exe
F3 - REG:win.ini: run=C:\WINNT\ctfmen.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Win2KService] C:\WINNT\system32\os\system32.exe
O4 - HKLM\..\Run: [ctfmen] C:\WINNT\ctfmen.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{54B1B358-61D6-4C05-98D3-8DCAD4089F9C}: NameServer = 202.136.162.11 202.136.163.11
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackHole Remote Control Services (BRC_Services) - Unknown owner - C:\WINNT\system32\brc_Server.exe" /service (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GrayPigeon_Hacker.com.cn - Unknown owner - C:\WINNT\Hacker.com.cn.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: llahl - Unknown owner - C:\Program Files\llah\llah.exe
O23 - Service: Å̹Å2007×îа汾·þÎñ¶Ë (pangu_service_name) - Unknown owner - C:\WINNT\system32\FireFoxUpdater.exe (file missing)
O23 - Service: PSEXESVC - Sysinternals - C:\WINNT\System32\PSEXESVC.EXE
O23 - Service: Remote Procedure Call System(RPCScc) (RpcScc) - Unknown owner - C:\WINNT\system32\Rpcscc.exe (file missing)
O23 - Service: svchost.exe (svcname) - Unknown owner - C:\WINNT\system32svchs0t.exe (file missing)
O23 - Service: system - Unknown owner - C:\WINNT\system\G_Server123
O23 - Service: Windows (Windows ) - Unknown owner - C:\WINNT\doc
O23 - Service: Windows Accounts Driver (windows_0) - Unknown owner - C:\WINNT\system32\Down(0).exe (file missing)
O23 - Service: winlogon - Unknown owner - C:\Program Files\winlogon.exe
O23 - Service: zhwe - Unknown owner - C:\WINNT\sx1101.exe
O23 - Service: Liang_liang_Server2.03 (¡¼ÁÁÁÁ¡½×¨ÒµÍêÃÀÆÆ½â) - Unknown owner - C:\WINNT\wappdx
================================================================================
Of the mentioned above, R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.nb4f===.com.cn, seems to be a pop-up which I am trying to clear.
Furthermore, I have only been visiting trustworthy websites and not downloaded anything onto my computer. Why is it that the trojans always seems present?
I hope to hear from you. Thanks.