This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] please examine my Hijack This log!

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1 Scan saved at 7:31:10 AM, on 2/18/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\wudfhost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Eset\nod32krn.exe C:\Program Files\CyberLink\Shared files\RichVideo.exe C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\WScript.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\Analog Devices\SoundMAX\SMTray.exe C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe C:\Program Files\Eset\nod32kui.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Cyberlink\Shared Files\brs.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\PC Connectivity Solution\ServiceLayer.exe C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe C:\Program Files\Opera\Opera.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Nokia\Nokia PC Suite 6\OneTouchAccess.exe C:\Program Files\Hijackthis\HijackThis.exe O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O3 - Toolbar: 2nd &Speech Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe O4 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE46E33-A43F-4BD9-A584-928AFA10E66C}: NameServer = 221.132.112.8 202.163.96.3 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe i post in a forum where some people for their personal hatred towards me , threatened me but i didnt notice till they stole some of my valuable information that i saved as text files on my hard drive.. e.g my girlfriend's cell number.. many of her sms that i stored as text file.. my family pictures missing too.. they called her and told all of our secrets so i knew i was hacked.. tried to install spyware doctor whose unistall format or exe file was already saved in hard drive but the pc got jammed before installation could complete.. i uninstalled spyware doctor in safe mode but during the process,it opened my browser without my will.. i downloaded spyware doctor again and it showed many spywares.. i am afraid my post will be long but i want to post INFECTIONS that spyware docotor removed.. Infection - C:\WINDOWS\SYSTEM32\drivers\svchost.exe Infection - 66.98.148.65, auto.search.msn.es Infection - 66.98.148.65, auto.search.msn.es Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, Userinit = C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\SYSTEM32\drivers\svchost.exe,C:\WINDOWS\SYSTEM32\drivers\svchost.exe, how did hackers got access to my hard drive? how can i prevent any future hijacking and please tell me if my system is clean now and can i trace these hackers? forgive me if my thread is long but pls understand that its a difficult situation for me.. thanks very much for your help! UPDATE on 19 feb: i knew it would take time for you guys to help so i installed zonealram pro to my pc.. every time i restart my pc and scan for spywares with zonealarm , it detects the same infection over and over again , no matter how many times i delete it keeps coming back! following is the detail of the infection win32.askyaya path: RegistryKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A2B7A0F0-B697-4A71-8D91-43443F57D7BB}
Hi adil8 and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Sorry to hear of your troubles. The internet can be a great place and it can be pretty ugly too.

Please download SDFix and save it to your Desktop.

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
  • Open the SDFix folder and double click on RunThis.bat to start the script.
  • Type Y and press Enter to begin the script.
  • It will start cleaning your PC and then prompt you to press any key to Reboot.
  • Press any key to restart the PC.
  • Your system will take longer than normal to restart as the fixtool will be removing files.
  • When the desktop loads the Fixtool will complete the removal and display Finished.
  • Press any key to end the script and to load your desktop icons.
  • A text file should automatically open, so please copy the contents and post them here. We also need you to post a new HijackThis log
DAVE bro I am thankful to you for your assistance!

SDFix: Version 1.144

Run by [removed] on Wed 02/20/2008 at 02:26 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Checking Files:

Trojan Files Found:

C:\autorun.inf - Deleted





Removing Temp Files…

ADS Check:



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-20 14:30:25
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:7e3bd9c1
"s2"=dword:5c67dfdf
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:8c,83,d3,be,6d,97,26,83,2d,7a,2a,bf,7a,b1,ba,85,c7,40,9f,79,70,..
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"h0"=dword:00000000
"ujdew"=hex:8c,83,d3,be,6d,97,26,83,2d,7a,2a,bf,7a,b1,ba,85,c7,40,9f,79,70,..
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"I:\\Keygens 16-01-08\\Keygens\\Opera Keygen\\Opera Keygen.exe"="I:\\Keygens 16-01-08\\Keygens\\Opera Keygen\\Opera Keygen.exe:*:Disabled:Opera Keygen"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Disabled:æTorrent"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Disabled:Bonjour"
"C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe"="C:\\Program Files\\CyberLink\\PowerDVD\\PowerDVD.exe:*:Disabled:CyberLink PowerDVD"
"C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Disabled:Google Talk"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Disabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Disabled:Windows Live Messenger 8.1 (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

Remaining Files:


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Fri 25 Jan 2008 101,764 A.SH. — "C:\daxian.exe"
Fri 25 Jan 2008 101,764 A.SH. — "C:\WINDOWS\system32\daxian.exe"
Sun 27 Jan 2008 180 A..H. — "C:\WINDOWS\system32\infopsvEV67s.dll"
Tue 8 May 2007 34,332 ..SH. — "C:\Documents and Settings\aadil8\Recycled\deskinf.pif"
Sun 6 Jan 2008 4,348 ..SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 8 May 2007 34,332 A.SH. — "C:\WINDOWS\system32\drivers\video.exe"
Sun 3 Feb 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 16 Jan 2008 444 …HR — "C:\Documents and Settings\aadil8\Application Data\SecuROM\UserData\securom_v7_01.bak"

Finished!

Logfile of HijackThis v1.99.1
Scan saved at 2:41:19 PM, on 2/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Nokia\Nokia PC Suite 6\OneTouchAccess.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: 2nd &Speech; Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] "C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Babylon Client] "C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" -AutoStart
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon; - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE46E33-A43F-4BD9-A584-928AFA10E66C}: NameServer = 221.132.112.8 202.163.96.3
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

can you please describe how i was hacked and what steps should i take to secure myself to prevent any future hijacking! you guys are doing a wonderful job and i really appreciate your efforts! God Bless You!

can you please describe how i was hacked and what steps should i take to secure myself to prevent any future hijacking! you guys are doing a wonderful job and i really appreciate your efforts! God Bless You!


Hi,
Unfortunately there is no positive way for us to know exactly how you were infected/hacked. I see some things and you have mentioned some things like the fact you did not have a firewall that contributed to this happening. At the end here when we determine you're clean I will post some advice on staying that way.
I will ask, do you use this PC for any financial transactions or other sensitive information. If so you should call your banks and advise them. Also change all of your passwords, ect…

Let's continue with the fix and we'll go from there.

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.



Please download ATF Cleaner here by Atribune. This program is for XP and Windows 2000 only.
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
  • Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


We Now Need To Boot Into Safemode Now

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


Run AVG


  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button This must done before saving the report
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
      [external image: Posted Image]
  • Right-click the AVG Tray Icon and select Exit.
  • Now copy the report back to this topic.


Restart into normal mode and post the AVG Log.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please do an online scan with Kaspersky WebScanner

You need to use Internet Explorer for this scan.

Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

Please also post a new HijackThis log and let me know how it's running.
hello DAVE bro.. i am afraid to tell you that i made a mistake.. after using ATF CLEANER , i went to SAFE MODE and RUN AVG and did everything according to your guidance till COMPLETE SYSTEM SCAN finished.. you said this to me : Important: Click on the Apply all Actions button This must done before saving the report but i saved report FIRST and then pressed APPLY ALL ACTIONS.. so it gave me a follwing message The file C:\system volume iformation\_restore{7cc60415-58de-490a-8655-82d3a4b86132}\rp168\a0243829.Exe/delay.Vbs cnt b quarantined bcz it s emebedded in archive C:\system volume information\_restore{7cc60415-58de-490a-8655-82d3a4b86132}\rp168\a0243829.Exe . . Do u want to quarantine whole archive? i pressed YES TO ALL till i got the message All actions have been applied. then i saved report again.. that was irresponsible of me.. i am sorry.. however here is the report..
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 2:30:41 AM 2/22/2008

+ Scan result:



C:\Program Files\Dvd-cloner\dvd-cloner.v.5.x-generic patch by Cerberus.exe -> Dropper.Agent.dlj : Cleaned with backup (quarantined).
F:\dvd cloner\dvd-cloner.v.5.x-generic patch by Cerberus.exe -> Dropper.Agent.dlj : Cleaned with backup (quarantined).
F:\spyware doc\Spyware Doctor v5.05.259 by TFT-TEAM.zip/Spyware Doctor v5.05.259 by TFT-TEAM.exe -> Dropper.Agent.dlj : Cleaned with backup (quarantined).
F:\spyware doc\Spyware Doctor v5.05.259 by TFT-TEAM\Spyware Doctor v5.05.259 by TFT-TEAM.exe -> Dropper.Agent.dlj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP180\A0277390.exe -> Logger.Banker.afq : Cleaned with backup (quarantined).
F:\utilities\WinRAR.3.50.B.1.CORPORATE.Edition\winrar.exe/winrar\crack\crack.exe -> Logger.Banker.zn : Cleaned with backup (quarantined).
F:\utilities\WinRAR.3.50.B.1.CORPORATE.Edition\winrar\crack\crack.exe -> Logger.Banker.zn : Cleaned with backup (quarantined).
E:\Great_Tuts-Part - 1\Great_Tuts_Part - 2\Great_Tuts_Part - 2\Great Tuts\Tutorials - blacksun.box.sk\coding\Batch File Programming.txt -> Trojan.Ankit : Cleaned with backup (quarantined).
F:\tutorials\Great_Tuts_Part - 2.rar/Great_Tuts_Part - 2\Great Tuts\Tutorials - blacksun.box.sk\coding\Batch File Programming.txt -> Trojan.Ankit : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP168\A0243829.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP168\A0243832.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP174\A0266057.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0276288.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0277280.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0277285.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP184\A0277835.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP185\A0279859.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP185\A0279861.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\WINDOWS\system32\daxian.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\daxian.exe/daxian.bat -> Trojan.KillAV.ec : Cleaned with backup (quarantined).
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Splash ID.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined).
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Splash Photo v4.05.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined).
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\SplashID.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined).
I:\Keygens 26-01-2008\Keygens 26-01-2008.zip/Keygens/Splash Photo v4.05.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined).
I:\Keygens 26-01-2008\Keygens\Splash Photo v4.05.exe -> Trojan.Pakes.av : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP168\A0243829.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP168\A0243832.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP174\A0266057.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0276288.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0277280.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0277285.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP184\A0277835.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP185\A0279859.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP185\A0279861.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\WINDOWS\system32\daxian.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
C:\daxian.exe/delay.vbs -> Trojan.Runner.x : Cleaned with backup (quarantined).
F:\ESET NOD 32 AntiVirus v 3.0.566.0 Final\New Addon\New Addon.exe -> Worm.VB.cj : Cleaned with backup (quarantined).


::Report end
Don't worry about the steps you took with AVG. Looks like it did what it needed to. Press on with the Kaspersky scan and we'll go from there. I will mention here though and food for thought in the future. Also, since you asked me how you were hacked, using cracks and keygens will definitely get you infected with trojans and other malware real quick. Simply avoiding that stuff in the future will give you a heck of a lot better chance of staying clean.
DAVE bro here is the kaspersky online scan.. man it took me more than two hours to finish.. i hate my pc lol
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, February 22, 2008 6:38:19 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 21/02/2008
Kaspersky Anti-Virus database records: 574925
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
L:\

Scan Statistics:
Total number of scanned objects: 35080
Number of viruses found: 10
Number of infected objects: 36
Number of suspicious objects: 0
Duration of the scan process: 01:10:43

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\aadil8\Application Data\Opera\Opera\mail\indexer\indexer.dat Object is locked skipped
C:\Documents and Settings\aadil8\Application Data\Opera\Opera\mail\lexicon\lexicon.dat Object is locked skipped
C:\Documents and Settings\aadil8\Application Data\Opera\Opera\mail\mailbase.dat Object is locked skipped
C:\Documents and Settings\aadil8\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\aadil8\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\aadil8\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\aadil8\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\aadil8\Local Settings\History\History.IE5\MSHist012008022220080223\index.dat Object is locked skipped
C:\Documents and Settings\aadil8\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\aadil8\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\aadil8\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\aadil8\Recycled\deskinf.pif Infected: Trojan-Dropper.Win32.Agent.ell skipped
C:\Documents and Settings\All Users\Application Data\CyberLink\BDNAV\BRF.dat Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\main.vbs Infected: Virus.VBS.Agent.f skipped
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Opera Keygen.zip/Opera Keygen.exe Infected: Backdoor.Win32.Agent.buy skipped
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Opera Keygen.zip ZIP: infected - 1 skipped
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\sw_ae-20080222-025305.log Object is locked skipped
C:\Program Files\ESET\cache\CACHE.NDB Object is locked skipped
C:\Program Files\ESET\infected\BCRKUQCA.NQF Infected: Trojan-Dropper.Win32.Agent.ell skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.cuu skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF/stream Infected: Trojan-Downloader.Win32.Zlob.cuu skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF NSIS: infected - 2 skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF PE-Crypt.XorPE: infected - 2 skipped
C:\Program Files\ESET\infected\CQVUHCCA.NQF Infected: Trojan-Downloader.Win32.VB.aso skipped
C:\Program Files\ESET\infected\NU2VGYAA.NQF Infected: Backdoor.Win32.Agent.buy skipped
C:\Program Files\ESET\logs\virlog.dat Object is locked skipped
C:\Program Files\ESET\logs\warnlog.dat Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP167\A0242816.exe Infected: Worm.Win32.AutoRun.cni skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP168\A0243830.vbs Infected: Virus.VBS.Agent.f skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP169\A0247854.pif Infected: Trojan-Dropper.Win32.Agent.ell skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP174\A0266058.exe Infected: Worm.Win32.AutoRun.cni skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP178\A0277283.vbs Infected: Virus.VBS.Agent.f skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP185\A0279860.vbs Infected: Virus.VBS.Agent.f skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279995.exe/data.rar/delay.vbs Infected: Trojan.VBS.Runner.x skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279995.exe/data.rar/daxian.bat Infected: Trojan.BAT.KillAV.ec skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279995.exe/data.rar Infected: Trojan.BAT.KillAV.ec skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279995.exe RarSFX: infected - 3 skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279996.exe/data.rar/delay.vbs Infected: Trojan.VBS.Runner.x skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279996.exe/data.rar/daxian.bat Infected: Trojan.BAT.KillAV.ec skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279996.exe/data.rar Infected: Trojan.BAT.KillAV.ec skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\A0279996.exe RarSFX: infected - 3 skipped
C:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP186\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\Internet Logs\fwpktlog.txt Object is locked skipped
C:\WINDOWS\ModemLog_Nokia 6680 USB Modem #2.txt Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
C:\WINDOWS\system32\drivers\video.exe Infected: Trojan-Dropper.Win32.Agent.ell skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\main.txt Infected: Virus.VBS.Agent.f skipped
C:\WINDOWS\system32\main.vbe Infected: Virus.VBS.Agent.f skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32temp2.exe Infected: Worm.Win32.AutoRun.cni skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\ESET NOD 32 AntiVirus v 3.0.566.0 Final\ESET_NOD_32_AntiVirus_v_3[1].0.566.0_Final_Retail.rar/ESET NOD 32 AntiVirus v 3.0.566.0 Final/New Addon/User & Pass v8.0.exe Infected: Trojan.Win32.Autoit.bg skipped
F:\ESET NOD 32 AntiVirus v 3.0.566.0 Final\ESET_NOD_32_AntiVirus_v_3[1].0.566.0_Final_Retail.rar RAR: infected - 1 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP182\A0277595.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
F:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP182\A0277595.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
F:\System Volume Information\_restore{7CC60415-58DE-490A-8655-82D3A4B86132}\RP182\A0277595.exe RarSFX: infected - 2 skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
I:\Keygens 26-01-2008\Keygens\Opera Keygen.zip/Opera Keygen.exe Infected: Backdoor.Win32.Agent.buy skipped
I:\Keygens 26-01-2008\Keygens\Opera Keygen.zip ZIP: infected - 1 skipped
I:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 6:46:45 AM, on 2/22/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\WScript.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\Nokia\Nokia PC Suite 6\OneTouchAccess.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gmail.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: 2nd &Speech Center - {CFE40ED8-564E-4693-A9D9-80DB70C8E460} - C:\PROGRA~1\2NDSPE~1\tts4ie.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [DrvLsnr] "C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe"
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Babylon Client] "C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" -AutoStart
O4 - HKLM\..\Run: [BDRegion] "C:\Program Files\Cyberlink\Shared Files\brs.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DDE46E33-A43F-4BD9-A584-928AFA10E66C}: NameServer = 221.132.112.8 202.163.96.3
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

DAVE bro you advised me not to use keygens and cracks to avoid being infected by a malware but dont you think that there are lot of people who dont buy softwares but rather get them registered with cracks and kegens etc , so you tend to do things which many others are doing thinking it wouldnt harm you as it didnt harm others.. so why it was me who got infected when lot of other people are doing the same?..please give me a few more tips so that i can't be hacked even by a geneous like you lol.. I am really thankful to you for your help!
Hi,

I would recommend you delete the following files:

C:\Documents and Settings\aadil8\Recycled\deskinf.pif
C:\main.vbs
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Opera Keygen.zip
C:\WINDOWS\system32\drivers\video.exe
C:\WINDOWS\system32\main.txt
C:\WINDOWS\system32\main.vbe
C:\WINDOWS\system32temp2.exe
I:\Keygens 26-01-2008\Keygens\Opera Keygen.zip


Question….where did you get your Nod32 Antivirus program from?

dont you think that there are lot of people who dont buy softwares but rather get them registered with cracks and kegens etc , so you tend to do things which many others are doing thinking it wouldnt harm you as it didnt harm others.. so why it was me who got infected when lot of other people are doing the same?


:smack:

Well…there are lots of people out there doing it…no doubt. While I don't have any statistics I will point a couple of things out that I've noticed in working hundreds of logs. Probably at least 3 out of 4 computers I see here have P2P/Torrent/File Sharing software on them, and we know what that is used for. You might get away with downloading 49 files without a problem….then #50 is a trojan, and bang you're done. It's not if you get infected playing with these things, it's when. Just a matter of time.

And to address your last sentence, take a look at these forums. Look how many posts are coming in every day, day after day, with people and their infected machines. Not just this forum but there are hundreds of these forums. With thousands and thousands of posts coming in every day. Probably more than half of those never even get answered. Just not enough helpers for the infected machines. This is a huge problem.

All I can do is warn you of the risks. I run a couple of virtual machines to test malware and removal techniques for myself. You want to know where I get the infections from? Take a guess…I fire up Limewire and I can have all kinds of nasties in about 10 minutes.

I'll give you some other free tools to put in place but just avoiding cracks and keygens, along with any file sharing, will go farther towards keeping you clean than any software out there, free or pay-for.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which may be infected anyway).

Click Start>Help and Support>Undo changes to your computer with System Restore
Select Create A Restore Point then click Next. Give it a name it and then click Create

Click Start>Run and type Cleanmgr
Click the More Options Tab.
Click Clean Up in the System Restore section.

In addition to updating and using what you currently have you may want to consider the following:

Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. Here is a list of some free and evaluation versions to try: AVG AntiVirus
Avast Antivirus Home Version–Free
Antivir Personal - Free
Online Scanners:
Trend Micro Housecall
Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. Here are some free and evalutation versions that provide
better security than the Windows Firewall. Comodo
ZoneAlarm Firewall
Outpost Firewall
For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Install Spybot - Search and Destroy - Spybot: Search And Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
A tutorial on installing & using this product can be found here:
Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

Install Ad-Aware - Ad-Aware SE You should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
A tutorial on installing & using this product can be found here:
Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install SpywareGuard - SpywareGuard provides a real-time protection solution against spyware that is a great addition to SpywareBlaster's protection method.
A tutorial on installing & using this product can be found here:
Using SpywareGuard to protect your computer from Spyware and Malware

Use IESpy-Ad -
IESpy-Ad will block access to malicious websites so you cannot be redirected to them from an infected site or email. Instructions for set up and use can be found at the website.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Here is a great link to a post here on securing your PC after an attack.
http://www.geekstogo.com/forum/index.php?a…;page=How_did_I

Good luck,
Dave
C:\Documents and Settings\aadil8\Recycled\deskinf.pif ..unable to locate
C:\main.vbs .. unable to locate
C:\Program Files\Alcohol Soft\Alcohol 120\Keygens 16-01-08\Keygens\Opera Keygen.zip ..removed
C:\WINDOWS\system32\drivers\video.exe .. unable to locate..
C:\WINDOWS\system32\main.txt .. removed
C:\WINDOWS\system32\main.vbe .. removed
C:\WINDOWS\system32temp2.exe .. removed
I:\Keygens 26-01-2008\Keygens\Opera Keygen.zip.. removed


DAVE that may sound stupid but i wasnt able to find three files as highlighted above.. i copied them to both SEARCH and RUN but didnt get them.. how do i remove em now.. pardon me for bothering you

Question….where did you get your Nod32 Antivirus program from?


i have been using this nod32 ever since i bought my pc a year ago and a friend of mine gave it to me via flash drive so eventhough i am regularly updating it , i dont know from where it was taken! dont you recommend nod32 for future use? lol am i asking too many questions.. okay forgive me.. i would soon be gone! thanks to you!
You're not asking too many questions.

From your Kaspersky log.

C:\Program Files\ESET\infected\BCRKUQCA.NQF Infected: Trojan-Dropper.Win32.Agent.ell skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.cuu skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF/stream Infected: Trojan-Downloader.Win32.Zlob.cuu skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF NSIS: infected - 2 skipped
C:\Program Files\ESET\infected\C2EC51AA.NQF PE-Crypt.XorPE: infected - 2 skipped
C:\Program Files\ESET\infected\CQVUHCCA.NQF Infected: Trojan-Downloader.Win32.VB.aso skipped
C:\Program Files\ESET\infected\NU2VGYAA.NQF Infected: Backdoor.Win32.Agent.buy skipped
F:\ESET NOD 32 AntiVirus v 3.0.566.0 Final\ESET_NOD_32_AntiVirus_v_3[1].0.566.0_Final_Retail.rar/ESET NOD 32 AntiVirus v 3.0.566.0 Final/New Addon/User & Pass v8.0.exe Infected: Trojan.Win32.Autoit.bg skipped
F:\ESET NOD 32 AntiVirus v 3.0.566.0 Final\ESET_NOD_32_AntiVirus_v_3[1].0.566.0_Final_Retail.rar RAR: infected - 1 skipped

Doesn't look like retail to me…that's all. It is great software, if it's working for you then….it may be fine.

I gave you some free legit. ones in my all clean so it's up to you.

From your Kaspersky log.


i am confused now.. that online kaspersky scanner thing doesnt give you an option to delete infected files.. are you saying that i should download and install kaspersky software to remove infected files? :(
No, the online Kaspersky scanner will not delete anything for you. You can either do it manually using Windows Explorer, or I can give you a tool with instructions to take care of it. Let me know if you would like that, Dave

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI