This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] google searchs redirected & other people emailing

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi I was running my system fairly unprotected for a while and now I have some problems:

Problem1. :(
When I search in Google, the Blue title at the top (and info) does not correspond with the green (web address) at the bottom. Sometimes searches work better than other times, but their usually I'm redirected to an irrelevant site.

Problem2.
When I log into hotmail instead of remembering my own address as requested, each time it comes up with a random [spam-like] address.

So far I have tried internet explorer 6 and firefox (3.0.3) with the same result

I then installed Spybot search and destroy and ad-aware and run them both a number of times.
I updated to xp sp2 and installed Kaspersky internet security. I ran a full scan and then ran a full scan in safe mode and safe mode administrator account.

This got rid of heaps of bad stuff but I'm still having the two problems mentioned above :wacko:

C: drive is my system drive

This is my current hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 8:24:04 PM, on 14/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1223820772609
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~2\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~2\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~2\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~2\KASPER~1\kloehk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


This the result of the Kaspersky scan:


Full Scan: completed 13/10/2008 5:53:16 PM (events: 70, objects: 436388, time: 02:50:54)
13/10/2008 5:53:16 PM Task completed
13/10/2008 5:53:14 PM Detected: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_swf.dll
13/10/2008 5:53:14 PM Detected: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_load.exe
13/10/2008 5:53:14 PM Untreated: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_clint.dll Skipped by user
13/10/2008 5:53:14 PM Detected: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_clint.dll
13/10/2008 5:53:13 PM Detected: not-a-virus:AdWare.Win32.EZula.bh N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0059.BIN
13/10/2008 5:53:12 PM Detected: not-a-virus:AdWare.Win32.Gator.1050 N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0058.BIN
13/10/2008 5:53:11 PM Detected: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0038.BIN
13/10/2008 5:53:11 PM Detected: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0037.BIN
13/10/2008 5:53:11 PM Untreated: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0036.BIN Skipped by user
13/10/2008 5:53:11 PM Detected: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0036.BIN
13/10/2008 5:53:06 PM Untreated: not-a-virus:AdWare.Win32.Gator.1050 N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\GetRight v4.5a Final\getrt45a.exe/WISE0087.BIN Skipped by user
13/10/2008 5:53:06 PM Detected: not-a-virus:AdWare.Win32.Gator.1050 N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\GetRight v4.5a Final\getrt45a.exe/WISE0087.BIN
13/10/2008 5:41:00 PM Detected: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_swf.dll
13/10/2008 5:41:00 PM Detected: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_load.exe
13/10/2008 5:41:00 PM Untreated: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_clint.dll Postponed
13/10/2008 5:40:55 PM Detected: not-a-virus:AdWare.Win32.Cydoor N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\PC-Telephone v3.5\pc-telephone.exe/cd_install_225.exe/cd_clint.dll
13/10/2008 5:38:37 PM Detected: not-a-virus:AdWare.Win32.EZula.bh N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0059.BIN
13/10/2008 5:38:36 PM Detected: not-a-virus:AdWare.Win32.Gator.1050 N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0058.BIN
13/10/2008 5:38:33 PM Detected: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0038.BIN
13/10/2008 5:38:33 PM Detected: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0037.BIN
13/10/2008 5:38:33 PM Untreated: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0036.BIN Postponed
13/10/2008 5:38:27 PM Detected: not-a-virus:AdWare.Win32.Aureate.a N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\go!zilla 4.1\go!zilla 4.1.exe/WISE0036.BIN
13/10/2008 5:38:27 PM Untreated: not-a-virus:AdWare.Win32.Gator.1050 N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\GetRight v4.5a Final\getrt45a.exe/WISE0087.BIN Postponed
13/10/2008 5:38:18 PM Detected: not-a-virus:AdWare.Win32.Gator.1050 N:\D\Programs\Virus Trojan, hijack software\Programs - Anti Virus - Utilities\GetRight v4.5a Final\getrt45a.exe/WISE0087.BIN
13/10/2008 5:00:20 PM Untreated: Trojan-Spy.Win32.KeyLogger.alo N:\D\Programs\NetObserve.exe/data0001/netobserve.exe/ASPack Postponed
13/10/2008 5:00:15 PM Detected: Trojan-Spy.Win32.KeyLogger.alo N:\D\Programs\NetObserve.exe/data0001/netobserve.exe/ASPack
13/10/2008 4:57:20 PM Untreated: not-a-virus:Porn-Dialer.Win32.Movienet N:\D\BACK UPS\DOGGOX - system of long ago\WINDOWS\Temporary Internet Files\Content.IE5\IXEDID01\dialer_activex[1].cab/dialer_activex.ocx Postponed
13/10/2008 4:57:20 PM Detected: not-a-virus:Porn-Dialer.Win32.Movienet N:\D\BACK UPS\DOGGOX - system of long ago\WINDOWS\Temporary Internet Files\Content.IE5\IXEDID01\dialer_activex[1].cab/dialer_activex.ocx
13/10/2008 4:57:03 PM Detected: http://www.viruslist.com/en/advisories/28083 N:\D\BACK UPS\DOGGOX - system of long ago\WINDOWS\SYSTEM\Macromed\Flash\swflash.ocx
13/10/2008 4:55:17 PM Detected: http://www.viruslist.com/en/advisories/12430 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\WinZip\WINZIP32.EXE
13/10/2008 4:55:07 PM Detected: http://www.viruslist.com/en/advisories/16653 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\Symantec\LiveUpdate\LUALL.EXE
13/10/2008 4:53:31 PM Detected: http://www.viruslist.com/en/advisories/30143 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\Microsoft Office\Office\WINWORD.EXE
13/10/2008 4:53:12 PM Detected: http://www.viruslist.com/en/advisories/31453 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\Microsoft Office\Office\POWERPNT.EXE
13/10/2008 4:52:23 PM Detected: http://www.viruslist.com/en/advisories/29320 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\Microsoft Office\Office\OUTLLIB.DLL
13/10/2008 4:52:19 PM Detected: http://www.viruslist.com/en/advisories/29321 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\Microsoft Office\Office\MSO9.DLL
13/10/2008 4:52:19 PM Detected: http://www.viruslist.com/en/advisories/31454 N:\D\BACK UPS\DOGGOX - system of long ago\Program Files\Microsoft Office\Office\EXCEL.EXE
13/10/2008 4:48:26 PM Detected: not-a-virus:AdWare.Win32.Gator.1050 N:\D\BACK UPS\DOGGOX - system of long ago\Downloaded carp**\AGSetup0608.exe/fsg-ag.exe
13/10/2008 4:48:24 PM Detected: not-a-virus:AdWare.Win32.OnFlow.d N:\D\BACK UPS\DOGGOX - system of long ago\Downloaded carp**\AGSetup0608.exe/ofStubIn.exe
13/10/2008 4:48:24 PM Untreated: not-a-virus:AdWare.Win32.BiSpy.ac N:\D\BACK UPS\DOGGOX - system of long ago\Downloaded carp**\AGSetup0608.exe/VX2.dll Postponed
13/10/2008 4:48:22 PM Detected: not-a-virus:AdWare.Win32.BiSpy.ac N:\D\BACK UPS\DOGGOX - system of long ago\Downloaded carp**\AGSetup0608.exe/VX2.dll
13/10/2008 4:18:27 PM Detected: http://www.viruslist.com/en/advisories/30975 E:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
13/10/2008 4:18:13 PM Detected: http://www.viruslist.com/en/advisories/31453 E:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
13/10/2008 4:18:12 PM Detected: http://www.viruslist.com/en/advisories/29320 E:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
13/10/2008 4:18:09 PM Detected: http://www.viruslist.com/en/advisories/31454 E:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
13/10/2008 4:16:16 PM Detected: http://www.viruslist.com/en/advisories/29321 E:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL
13/10/2008 4:09:48 PM Detected: http://www.viruslist.com/en/advisories/31010 C:\windows\system32\java.exe
13/10/2008 3:47:01 PM Detected: http://www.viruslist.com/en/advisories/30975 C:\Program Files\microsoft office\office11\winword.exe
13/10/2008 3:46:59 PM Detected: http://www.viruslist.com/en/advisories/31453 C:\Program Files\microsoft office\office11\POWERPNT.EXE
13/10/2008 3:46:55 PM Detected: http://www.viruslist.com/en/advisories/29320 C:\Program Files\microsoft office\office11\outlook.exe
13/10/2008 3:46:46 PM Detected: http://www.viruslist.com/en/advisories/31454 C:\Program Files\microsoft office\office11\excel.exe
13/10/2008 3:45:31 PM Detected: http://www.viruslist.com/en/advisories/31010 C:\Program Files\Java\jre1.6.0_06\bin\java.exe
13/10/2008 3:42:18 PM Detected: http://www.viruslist.com/en/advisories/29321 C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL
13/10/2008 3:39:03 PM Detected: http://www.viruslist.com/en/advisories/30832 C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.dll
13/10/2008 3:11:31 PM Untreated: Trojan-PSW.Win32.Agent.kxr C:\Documents and Settings\Philip K\lxmlohf.exe Postponed
13/10/2008 3:11:30 PM Untreated: Trojan-PSW.Win32.Agent.kyh C:\Documents and Settings\Philip K\vddtyqd.exe Postponed
13/10/2008 3:11:28 PM Detected: Trojan-PSW.Win32.Agent.kxr C:\Documents and Settings\Philip K\lxmlohf.exe
13/10/2008 3:11:28 PM Detected: Trojan-PSW.Win32.Agent.kyh C:\Documents and Settings\Philip K\vddtyqd.exe
13/10/2008 3:11:12 PM Detected: http://www.viruslist.com/en/advisories/29434 C:\Documents and Settings\All Users\Application Data\{2CDB37F9-8421-4077-9FE5-8D1B250A0445}\mia.lib
13/10/2008 3:02:22 PM Task started
13/10/2008 2:30:39 PM Task stopped
13/10/2008 2:24:14 PM Untreated: Rootkit.Win32.Pakes.g C:\System Volume Information\_restore{CB8918D1-4669-4805-8B2B-D18181DC4E90}\RP335\A0047672.sys Postponed
13/10/2008 2:24:14 PM Detected: Rootkit.Win32.Pakes.g C:\System Volume Information\_restore{CB8918D1-4669-4805-8B2B-D18181DC4E90}\RP335\A0047672.sys
13/10/2008 2:15:52 PM Detected: http://www.viruslist.com/en/advisories/31010 C:\windows\system32\java.exe
13/10/2008 2:14:14 PM Detected: http://www.viruslist.com/en/advisories/31106 C:\Program Files\Mozilla Firefox\firefox.exe
13/10/2008 2:13:05 PM Detected: http://www.viruslist.com/en/advisories/30975 C:\Program Files\microsoft office\office11\winword.exe
13/10/2008 2:12:48 PM Detected: http://www.viruslist.com/en/advisories/31453 C:\Program Files\microsoft office\office11\POWERPNT.EXE
13/10/2008 2:12:34 PM Detected: http://www.viruslist.com/en/advisories/31454 C:\Program Files\microsoft office\office11\excel.exe
13/10/2008 2:12:16 PM Detected: http://www.viruslist.com/en/advisories/29320 C:\Program Files\microsoft office\office11\outlook.exe
13/10/2008 2:09:54 PM Task started
Full Scan: completed 13/10/2008 5:53:16 PM (events: 70, objects: 436388, time: 02:50:54)
13/10/2008 1:59:39 PM Task started
13/10/2008 1:59:55 PM Task stopped
Full Scan: completed 13/10/2008 5:53:16 PM (events: 70, objects: 436388, time: 02:50:54)
13/10/2008 1:32:43 PM Task completed
13/10/2008 1:24:52 PM Deleted: Rootkit.Win32.Pakes.g C:\windows\system32\drivers\heuhieacmiwjzfd.sys
13/10/2008 1:24:48 PM Deleted: Rootkit.Win32.Pakes.g HKLM\System\ControlSet003\Services\pjdti\pjdti
13/10/2008 1:24:43 PM Detected: Rootkit.Win32.Pakes.g C:\windows\system32\drivers\heuhieacmiwjzfd.sys
13/10/2008 1:24:42 PM Task started
Full Scan: completed 13/10/2008 5:53:16 PM (events: 70, objects: 436388, time: 02:50:54)
13/10/2008 12:07:29 PM Task started
13/10/2008 12:09:13 PM Task stopped
Full Scan: completed 13/10/2008 5:53:16 PM (events: 70, objects: 436388, time: 02:50:54)
13/10/2008 11:21:39 AM Task started
13/10/2008 11:23:37 AM Detected: http://www.viruslist.com/en/advisories/31106 C:\Program Files\Mozilla Firefox\firefox.exe
13/10/2008 11:25:54 AM Detected: http://www.viruslist.com/en/advisories/28506 C:\Program Files\microsoft office\office11\excel.exe
13/10/2008 11:25:55 AM Detected: http://www.viruslist.com/en/advisories/29320 C:\Program Files\microsoft office\office11\outlook.exe
13/10/2008 11:25:59 AM Detected: http://www.viruslist.com/en/advisories/30143 C:\Program Files\microsoft office\office11\winword.exe
13/10/2008 11:26:07 AM Detected: http://www.viruslist.com/en/advisories/31106 C:\Program Files\Mozilla Firefox\firefox.exe
13/10/2008 11:26:17 AM Detected: http://www.viruslist.com/en/advisories/31010 C:\windows\system32\java.exe
13/10/2008 11:37:59 AM Detected: http://www.viruslist.com/en/advisories/29434 C:\Documents and Settings\All Users\Application Data\{2CDB37F9-8421-4077-9FE5-8D1B250A0445}\mia.lib
13/10/2008 12:01:57 PM Task stopped
13/10/2008 12:07:43 PM Task started
13/10/2008 12:12:55 PM Detected: Trojan-PSW.Win32.Agent.kxr C:\Documents and Settings\Philip K\Local Settings\Temporary Internet Files\Content.IE5\AL5ARYH0\CA4MQP6T
13/10/2008 12:12:55 PM Untreated: Trojan-PSW.Win32.Agent.kxr C:\Documents and Settings\Philip K\Local Settings\Temporary Internet Files\Content.IE5\AL5ARYH0\CA4MQP6T Postponed
13/10/2008 12:13:00 PM Detected: Rootkit.Win32.Pakes.g C:\Documents and Settings\Philip K\Local Settings\Temporary Internet Files\Content.IE5\AL5ARYH0\CAEV0X7A/#
13/10/2008 12:13:01 PM Untreated: Rootkit.Win32.Pakes.g C:\Documents and Settings\Philip K\Local Settings\Temporary Internet Files\Content.IE5\AL5ARYH0\CAEV0X7A/# Postponed
13/10/2008 12:21:42 PM Task stopped
13/10/2008 12:22:07 PM Task started
13/10/2008 12:28:38 PM Detected: Trojan.JS.Agent.db C:\Documents and Settings\Philip K\Local Settings\Temporary Internet Files\Content.IE5\S78FAPGV\v53[1].js
13/10/2008 12:28:40 PM Untreated: Trojan.JS.Agent.db C:\Documents and Settings\Philip K\Local Settings\Temporary Internet Files\Content.IE5\S78FAPGV\v53[1].js Postponed
13/10/2008 12:42:08 PM Detected: http://www.viruslist.com/en/advisories/30832 C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.dll
13/10/2008 12:45:54 PM Detected: http://www.viruslist.com/en/advisories/29321 C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL
13/10/2008 12:49:21 PM Detected: http://www.viruslist.com/en/advisories/31010 C:\Program Files\Java\jre1.6.0_06\bin\java.exe
13/10/2008 12:50:54 PM Detected: http://www.viruslist.com/en/advisories/31454 C:\Program Files\microsoft office\office11\excel.exe
13/10/2008 12:50:58 PM Detected: http://www.viruslist.com/en/advisories/29320 C:\Program Files\microsoft office\office11\outlook.exe
13/10/2008 12:51:06 PM Detected: http://www.viruslist.com/en/advisories/31453 C:\Program Files\microsoft office\office11\POWERPNT.EXE
13/10/2008 12:51:30 PM Detected: http://www.viruslist.com/en/advisories/30975 C:\Program Files\microsoft office\office11\winword.exe
13/10/2008 12:51:53 PM Detected: http://www.viruslist.com/en/advisories/31106 C:\Program Files\Mozilla Firefox\firefox.exe
13/10/2008 1:21:20 PM Detected: http://www.viruslist.com/en/advisories/31010 C:\windows\system32\java.exe
13/10/2008 1:22:59 PM Detected: Rootkit.Win32.Pakes.g C:\windows\system32\drivers\heuhieacmiwjzfd.sys
13/10/2008 1:23:00 PM Untreated: Rootkit.Win32.Pakes.g C:\windows\system32\drivers\heuhieacmiwjzfd.sys Postponed
13/10/2008 1:25:07 PM Detected: Trojan.JS.Agent.db E:\Documents and Settings\Philip Kenworthy\Local Settings\Temporary Internet Files\Content.IE5\AHONK9YH\v53[1].js
13/10/2008 1:25:07 PM Untreated: Trojan.JS.Agent.db E:\Documents and Settings\Philip Kenworthy\Local Settings\Temporary Internet Files\Content.IE5\AHONK9YH\v53[1].js Postponed
13/10/2008 1:27:15 PM Detected: http://www.viruslist.com/en/advisories/29321 E:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL
13/10/2008 1:29:11 PM Detected: http://www.viruslist.com/en/advisories/29320 E:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
13/10/2008 1:29:21 PM Detected: http://www.viruslist.com/en/advisories/31453 E:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
13/10/2008 1:29:22 PM Detected: http://www.viruslist.com/en/advisories/31454 E:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
13/10/2008 1:29:30 PM Detected: http://www.viruslist.com/en/advisories/30975 E:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
Full Scan: completed 13/10/2008 5:53:16 PM (events: 70, objects: 436388, time: 02:50:54)
13/10/2008 11:17:57 AM Task started
13/10/2008 11:26:06 AM Task completed




And this is the result of the fixwareout scan



~~~~~ Prerun check

Could not flush the DNS Resolver Cache: Function failed during execution.


System was rebooted successfully.

~~~~~ Postrun check
HKLM\SOFTWARE\~\Winlogon\ "System"=""
….
….
~~~~~ Misc files.
….
~~~~~ Checking for older varients.
….

~~~~~ Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C-Media Mixer"="Mixer.exe /startup"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"Samsung Common SM"="\"C:\\WINDOWS\\Samsung\\ComSMMgr\\ssmmgr.exe\" /autorun"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"CloneDVDElbyDelay"="\"C:\\Program Files\\Elaborate Bytes\\CloneDVD\\ElbyCheck.exe\" /L ElbyDelay"
"AVP"="\"C:\\Program Files\\Kaspersky Lab\\Kaspersky Internet Security 2009\\avp.exe\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
….
Hosts file was reset, If you use a custom hosts file please replace it…
~~~~~ End report ~~~~~



Kaspersky has fixed all of the problems (aside from the vunerabilites) that it found.


Is there anyone who can help me?
:wavey:

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post a log in the HJT forum and wait for help.

Hi Jane Mack and welcome to What the Tech :).

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:
  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!.
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use.
    Be assured, any links I give are safe
Extra note: Please be aware as I am still in training all of my fixes/posts require prior checking by a Expert. So some delays may be inevitable, please be patient and I will reply again asap.
Hi :)

I apoligise about myself replying late, unforeseen circumstances, please read the below and let myself know your decision, either way I will provide advice.

—-

Unfortuanately my research has reavealed your computer hadmultiple infections, including a backdoor/rootkit. The aforementioned gives intruders complete control of your computer, logs your keystrokes, steal personal information, etc.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of infection, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can attempt to clean this machine but i can't guarantee that it will be 100% secure afterwards.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next post.
Hi Dakeyras

Thanks a lot for the help. :)

I kept on playing with my computer on the night that I posted until something in hijack this seemed to work. Since then the worst symptoms seem to have gone. I deleted “reg keys” with hijack this going on the info that HJT tells you and from 2 threads on this forum.

I’ve 2weeks left of the final year of my music degree so I’ve just working at that as hard as I can and thus I didn’t check again after the first day of no reply.

Since reading your reply I have changed my passwords for my all my online banking and other financial online things (from a clean computer as recommended).

One thing that seems to be happening now is that windows explorer always hangs and waits when i try to shut down. it give the typical ending program msg (with the end now option) that you get when program are still running. It happens every time i shut it down.

I’m now gonna read more of the info at the links that you provided:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

here is my new HJT log done with virus software disabled and no other programs running:

Logfile of HijackThis v1.99.1
Scan saved at 11:16:08 PM, on 19/10/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1223820772609
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~2\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~2\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~2\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~2\KASPER~1\kloehk.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Kaspersky Internet Security (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" -r (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

Thanks again I hope to hear from you soon
Can hackers see what i see on my monitor? :o My bank password is entered with a virtual keyboard not with mouse clicks. so it should be safe from key loggers? If they can see wots on my monitor then I could have been in trouble. How much access do you think they could have gained? could they have run searches for files on my entire system and uploaded anything they thought was interesting? A scary thought The computer was essentially completely unprotected for several days maybe up to a week whilst the worst of the symptoms were happening. and it was on the net continuously well it would have been if one of the symptoms were not the connection dropping out after about 20 min. :smack: I have a question in regards to a Microsoft home network that I recently setup via a 4way ADSL router. will the damaged computer compromise the security of the other to computers on the network? If you share folder on the local network can these then be accessed from the internet or is it are these things separate from each other? have all these computers been compromised? Please tell me if this is not best place to for these questions Maybe I should reformat? thanks again

My bank password is entered with a virtual keyboard not with mouse clicks. so it should be safe from key loggers? If they can see wots on my monitor then I could have been in trouble.

sorry, that's supposed to read:
My bank password is entered with a virtual keyboard with mouse clicks. so it should be safe from key loggers? If they can see wots on my monitor then I could be in trouble.
Hi Jane Mack :) Best wishes/good luck for the completion of your music degree :thumbup: . Ok back to your computer. I appreciate your concern with this matter and this reply really is just a courtesy so you are aware I am here to assist if required :) Re: My second post to your good self a Format is advised but if you wish to go ahead with a attempted malware removal. I will to the best of my abilities attempt to eradicative all the malware but this is not 100% guaranteed due to the nature of the infections that need to be dealt with unfortunately. In regard to your other query's, yes I can answer them but because I am still in training all of my replies have to be approved by the Anti-Malware Expert whose guidance I am working under. So please be patient about this, thank you. On another note please refrain from any more self fixes as this may hinder the malware removal process and please re-enable your Anti-Virus software as this is a very un-safe practice when accessing the Internet and may complicate matters further. So in the meantime if you could let myself know if you wish to go ahead with a malware removal or not and I will seek approval for the answers to your various query's ok :)
Hi :)

think I'll reformat just to be safe.

Thanks for the advice

And best of luck with all future projects

jm

You're welcome! and I respect your decision. Thank you for the well wishes.

I advise you read this guide as it will prove of benefit: Windows XP - Reformat and Re-install Guide

Also I advice you carry out the same re a reformat for the other computers on your network as there is high probability they are compromised as well.

If you have any further questions do not hesitate to ask :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI