This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Please Help, Viruses

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 8:56:49 PM, on 1/28/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS2\System32\smss.exe
C:\WINDOWS2\system32\winlogon.exe
C:\WINDOWS2\system32\services.exe
C:\WINDOWS2\system32\lsass.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\system32\svchost.exe
C:\WINDOWS2\system32\rxjddnvj.exe
C:\WINDOWS2\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS2\system32\userinit.exe,C:\WINDOWS2\system32\rxjddnvj.exe,
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS2\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [mzunexsp] regsvr32 /u "C:\Documents and Settings\All Users\Application Data\mzunexsp.dll"
O4 - HKLM\..\Run: [drmsrv32] C:\DOCUME~1\Chisom\LOCALS~1\Temp\stmhost .exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA3262] command /c del "C:\WINDOWS2\7search.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5660] cmd /c del "C:\WINDOWS2\7search.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1212] command /c del "C:\WINDOWS2\hcwprn.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4241] cmd /c del "C:\WINDOWS2\hcwprn.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3317] command /c del "C:\WINDOWS2\wbeCheck.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4444] cmd /c del "C:\WINDOWS2\wbeCheck.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9451] command /c del "C:\WINDOWS2\kvnab.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5689] cmd /c del "C:\WINDOWS2\kvnab.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9116] command /c del "C:\WINDOWS2\wbeInst$.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5704] cmd /c del "C:\WINDOWS2\wbeInst$.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2725] command /c del "C:\WINDOWS2\kvnab$.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC788] cmd /c del "C:\WINDOWS2\kvnab$.exe_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3701] command /c del "C:\WINDOWS2\settn.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4356] cmd /c del "C:\WINDOWS2\settn.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9149] command /c del "C:\WINDOWS2\pbsysie.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9129] cmd /c del "C:\WINDOWS2\pbsysie.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3310] command /c del "C:\WINDOWS2\kvnab.dll_tobedeleted"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7916] cmd /c del "C:\WINDOWS2\kvnab.dll_tobedeleted"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [Aols] "C:\DOCUME~1\Chisom\APPLIC~1\YMBOLS~1\lsass.exe" -vt yazb
O4 - HKCU\..\Run: [QdrModule12] "C:\Program Files\QdrModule\QdrModule12.exe"
O4 - HKCU\..\Run: [Tsh] "C:\Program Files\?dobe\l?ass.exe"
O4 - HKCU\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS2\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS2\web\related.htm
O16 - DPF: {1A26F07F-0D60-4835-91CF-1E1766A0EC56} (WebInstall Class) - http://scanner2.malware-scan.com/setup/webinst.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab
O16 - DPF: {EA6246B4-F380-443F-8727-9AEA3371146C} (CPlayFirstWeddingDashControl Object) - http://aolsvc.aol.com/onlinegames/free-tri…sh.1.0.0.47.cab
O21 - SSODL: Spybot - Search & Destroy_is1 - {77FF30CC-211B-057C-B3F4-8DEE5880FD1F} - c:\program files\spybot - search & destroy\uaynde32.dll
O23 - Service: avp - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" -r (file missing)
O23 - Service: avp - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp .exe" -r (file missing)
O23 - Service: Security Service (IIKD) - Unknown owner - C:\WINDOWS2\System32\svcd\svchost.exe



SDFix: Version 1.132

Run by [removed] on Mon 01/28/2008 at 11:36 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\DOCUME~1\Chisom\Desktop\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINDOWS2\urkqpteg\1.png - Deleted
C:\WINDOWS2\urkqpteg\2.png - Deleted
C:\WINDOWS2\urkqpteg\3.png - Deleted
C:\WINDOWS2\urkqpteg\4.png - Deleted
C:\WINDOWS2\urkqpteg\5.png - Deleted
C:\WINDOWS2\urkqpteg\6.png - Deleted
C:\WINDOWS2\urkqpteg\7.png - Deleted
C:\WINDOWS2\urkqpteg\8.png - Deleted
C:\WINDOWS2\urkqpteg\9.png - Deleted
C:\WINDOWS2\urkqpteg\bottom-rc.gif - Deleted
C:\WINDOWS2\urkqpteg\config.png - Deleted
C:\WINDOWS2\urkqpteg\content.png - Deleted
C:\WINDOWS2\urkqpteg\download.gif - Deleted
C:\WINDOWS2\urkqpteg\frame-bg.gif - Deleted
C:\WINDOWS2\urkqpteg\frame-bottom-left.gif - Deleted
C:\WINDOWS2\urkqpteg\frame-h1bg.gif - Deleted
C:\WINDOWS2\urkqpteg\head.png - Deleted
C:\WINDOWS2\urkqpteg\icon.png - Deleted
C:\WINDOWS2\urkqpteg\indexwp.html - Deleted
C:\WINDOWS2\urkqpteg\main.css - Deleted
C:\WINDOWS2\urkqpteg\memory-prots.png - Deleted
C:\WINDOWS2\urkqpteg\net.png - Deleted
C:\WINDOWS2\urkqpteg\pc.gif - Deleted
C:\WINDOWS2\urkqpteg\pc-mag.gif - Deleted
C:\WINDOWS2\urkqpteg\poloska1.png - Deleted
C:\WINDOWS2\urkqpteg\poloska2.png - Deleted
C:\WINDOWS2\urkqpteg\poloska3.png - Deleted
C:\WINDOWS2\urkqpteg\promowp1.html - Deleted
C:\WINDOWS2\urkqpteg\promowp2.html - Deleted
C:\WINDOWS2\urkqpteg\promowp3.html - Deleted
C:\WINDOWS2\urkqpteg\promowp4.html - Deleted
C:\WINDOWS2\urkqpteg\promowp5.html - Deleted
C:\WINDOWS2\urkqpteg\reg.png - Deleted
C:\WINDOWS2\urkqpteg\repair.png - Deleted
C:\WINDOWS2\urkqpteg\scr-1.png - Deleted
C:\WINDOWS2\urkqpteg\scr-2.png - Deleted
C:\WINDOWS2\urkqpteg\start.png - Deleted
C:\WINDOWS2\urkqpteg\styles.css - Deleted
C:\WINDOWS2\urkqpteg\top-rc.gif - Deleted
C:\WINDOWS2\urkqpteg\vline.gif - Deleted
C:\WINDOWS2\urkqpteg\wp.png - Deleted
C:\WINDOWS2\PerfInfo\8IaKafXpu8wp.exe - Deleted
C:\WINDOWS2\hotporn.exe - Deleted
C:\WINDOWS2\ie_32.exe - Deleted
C:\WINDOWS2\system32\CID - Deleted
C:\WINDOWS2\system32\svcd\svchost.exe - Deleted
C:\WINDOWS2\system32\SvcNm - Deleted
C:\WINDOWS2\system32\TmpX.exe - Deleted
C:\WINDOWS2\system32\upds.log - Deleted
C:\WINDOWS2\system32\url1 - Deleted
C:\WINDOWS2\system32\url2 - Deleted
C:\WINDOWS2\system32\url3 - Deleted
C:\WINDOWS2\hotporn.exe - Deleted
C:\WINDOWS2\ie_32.exe - Deleted



Folder C:\Program Files\Dot1XCfg - Removed
Folder C:\Program Files\Temporary - Removed
Folder C:\WINDOWS2\PerfInfo - Removed
Folder C:\WINDOWS2\system32\svcd - Removed


Removing Temp Files…

ADS Check:




Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-28 23:41:26
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

Remaining Files:
—————
C:\WINDOWS2\hotporn.exe Found
C:\WINDOWS2\ie_32.exe Found
C:\WINDOWS2\hotporn.exe Found
C:\WINDOWS2\ie_32.exe Found

File Backups: - C:\DOCUME~1\Chisom\Desktop\SDFix\backups\backups.zip

Files with Hidden Attributes:


Finished!

Any assistance, would be appreciated!!
Hi Chisom and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Make sure to make a backup of any data that you have created, such as documents, pictures, music, ect… before we begin the fix.

I removed your other post from yesterday. Please don't start more than one topic. Reply to this thread only.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Well as you can see SDFix did quite a bit, but you are still quite infected.

Please download ComboFix by sUBs from HERE or HERE
  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..

Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Dave, Happy Wednesday!! Thanks so much for your Help!! I tried running the combofix the other night when I was running the SDfix, Spybot, and everything else I could think of, but it wouldn't run. So I just downloaded it again from your link and this is what happened. I tried to attach a doc with the screen print, with no success. The error message was "C:\Documents and Settings\Chisom\Desktop\cfldr not in expected location. Inform sUBs now!!" The error from yesterday was "Windows cannot find '.bat'. Make sure you typed the name correctly, and then try again. To search for a file, click the Start button, and then click Search." Chisom

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI