ComputerForum.com ComputerForum.com  

Go Back   Computer Forum > Computer Software > Computer Security

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
Old 07-03-2008, 06:15 PM   #1 (permalink)
Bronze Member
 
Join Date: Jul 2008
Posts: 25
Default Plz help me with trojan zlob.pornadvertiser.ba

Hello friends, plz help me., my computer has a serious problem and am not able to do anything. i get an error saying that my computer has zlob.pornadvertiser.ba virus and nothing seems to be working. the alert keeps popping. browser is closing everytime I click on anything. i got this site by logging through a different login. plz help

I saw a few responses on the site and i have got the log from hijack this. and remaining whatever was there in the post i was not able to understand.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:58:13 PM, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32krn.exe
D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Eset\nod32kui.exe
D:\Program Files\BlazeVideo\BlazeDVD 5 Professional\MediaDetector.exe
D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Console Flash v.4.1 - {BCC8A4AB-C055-461E-B4B5-1B0EA8647897} - C:\WINDOWS\system32\confl.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdvnf.exe] C:\WINDOWS\system32\kdvnf.exe
O4 - HKCU\..\Run: [BlazeServoTool] "D:\Program Files\BlazeVideo\BlazeDVD 5 Professional\MediaDetector.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\G oogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "D:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .MOV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7F78793-C4E9-43AC-B077-EC4B720BB791}: NameServer = 218.248.240.23,218.248.240.135
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspn et_state.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe

--
End of file - 6014 bytes
mand1 is offline   Reply With Quote


Old 07-03-2008, 06:22 PM   #2 (permalink)
Bronze Member
 
grk77536's Avatar
 
Join Date: Jun 2008
Location: DP, TX
Posts: 45
Default

do you have a spyware/adware blocker? I had a similar problem where a software title kept installing by itself and caused a huge memory dump.
I had to format my hdd and start over viruses suck!
__________________
CPU: AMD phenom quad core@ 2.4ghz
Mobo: geForce 6150m-M2 AMD socket 2+
Ram: 2 gigs Corsair ddr2 800mhz
Graphics: ATI hd4850@ 650/1090/1985mhz
PSU: Tru Power 480 watt
Case: Slickdealz Custom Case
grk77536 is offline   Reply With Quote
Old 07-03-2008, 06:26 PM   #3 (permalink)
Bronze Member
 
Join Date: Jul 2008
Posts: 25
Default

i tried installing but currently no online tool is working here. i tried nod32 it did not work and i tried uniblue, even that did not show it up
mand1 is offline   Reply With Quote
Old 07-03-2008, 06:33 PM   #4 (permalink)
Diamond Member
 
Punk's Avatar
 
Join Date: Jan 2007
Location: France
Age: 19
Posts: 5,283
Default

Hello,


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

Download and Run ComboFix
If you already have Combofix, please delete this copy and download it again as it's being updated regularly.Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.
__________________
Punk's Website making and registering tutorial!

Rise And Fall, Rage And Grace

The Offspring!

Huck it!
I just want to be who I want to be
guess that's hard for others to see
Punk is offline   Reply With Quote
Old 07-03-2008, 07:48 PM   #5 (permalink)
Bronze Member
 
Join Date: Jul 2008
Posts: 25
Default

Thanks a ton for your quick solution to my problem. You were my savior today. I followed all the steps. Currently I am sending this from my login and its working, I dont know if the virus is deleted completely. But I dont have those icons on the desktop anymore. I dont even get pop ups. Does this mean that there is no more virus in my computer.

This is the report for sdfix


SDFix: Version 1.201
Run by mand on Thu 07/03/2008 at 10:40 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Name :
SysLibrary

Path :
\??\C:\WINDOWS\system32\DefLib.sys

SysLibrary - Deleted



Restoring Default Security Values
Restoring Default Hosts File
-------

This is the log file of combifix

ComboFix 08-07-02.5 - mand 2008-07-03 22:49:14.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.79 [GMT 5.5:30]
Running from: C:\Documents and Settings\mand\Desktop\ComboFix.exe
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\mand\Desktop\BDSM galleries.URL
C:\Documents and Settings\mand\Desktop\CP illegal content.URL
C:\Documents and Settings\mand\Desktop\Uncensored porn.URL
C:\WINDOWS\system32\drivers\svchost.exe
C:\WINDOWS\system32\igfxhk.dll
C:\WINDOWS\system32\kdvnf.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\ntload.dll
C:\WINDOWS\system32\sex1.ico
C:\WINDOWS\system32\sex2.ico
C:\WINDOWS\system32\sex3.ico
C:\WINDOWS\system32\svcp.csv
C:\WINDOWS\system32\winsub.xml
C:\WINDOWS\system32\winupdate.exe
C:\WINDOWS\system32\wscmp.dll
C:\WINDOWS\system32\zlib.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_SysLibrary


((((((((((((((((((((((((( Files Created from 2008-06-03 to 2008-07-03 )))))))))))))))))))))))))))))))
.

2008-07-03 22:36 . 2008-07-03 22:36 <DIR> d-------- C:\WINDOWS\ERUNT
2008-07-03 22:31 . 2008-07-04 14:46 <DIR> d-------- C:\SDFix
2008-07-03 22:26 . 2008-07-03 22:26 <DIR> d-------- C:\Documents and Settings\neel\Phone Browser
2008-07-03 22:26 . 2008-07-03 22:26 <DIR> d-------- C:\Documents and Settings\neel\Application Data\Datalayer
2008-07-03 20:46 . 2008-07-03 20:46 <DIR> d-------- C:\Documents and Settings\neel\Application Data\Apple Computer
2008-07-03 19:55 . 2008-07-03 19:55 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-03 16:06 . 2008-07-03 16:06 <DIR> d-------- C:\Program Files\SpyNoMore
2008-07-03 16:06 . 2008-07-03 16:06 1,152 --a------ C:\WINDOWS\system32\windrv.sys
2008-07-03 16:05 . 2008-07-03 16:05 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-07-03 15:45 . 2008-07-03 15:45 262,144 --a------ C:\WINDOWS\system32\wscmp.dll.tmp
2008-07-03 15:41 . 2008-07-03 15:41 0 --a------ C:\WINDOWS\system32\sex3.ico.tmp
2008-07-03 15:40 . 2008-07-03 15:40 0 --a------ C:\WINDOWS\system32\sex2.ico.tmp
2008-07-03 15:40 . 2008-07-03 15:40 0 --a------ C:\WINDOWS\system32\sex1.ico.tmp
2008-06-19 10:46 . 2008-06-19 10:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\InterVideo
2008-06-19 10:46 . 2002-09-27 07:53 9,856 --------- C:\WINDOWS\system32\drivers\pfc.sys
2008-06-19 10:45 . 2001-12-10 17:42 204,800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2008-06-19 10:45 . 2001-12-10 17:42 200,704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2008-06-19 10:45 . 2001-12-10 17:42 192,512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2008-06-19 10:45 . 2001-12-10 17:42 192,512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2008-06-19 10:45 . 2001-12-10 17:42 188,416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2008-06-19 10:45 . 2001-12-10 17:42 20,480 --a------ C:\WINDOWS\system32\IVIresize.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) ))
.
1998-12-08 13:53 99,840 ----a-w C:\Program Files\Common Files\IRAABOUT.DLL
1998-12-08 13:53 70,144 ----a-w C:\Program Files\Common Files\IRAMDMTR.DLL
1998-12-08 13:53 48,640 ----a-w C:\Program Files\Common Files\IRALPTTR.DLL
1998-12-08 13:53 31,744 ----a-w C:\Program Files\Common Files\IRAWEBTR.DLL
1998-12-08 13:53 186,368 ----a-w C:\Program Files\Common Files\IRAREG.DLL
1998-12-08 13:53 17,920 ----a-w C:\Program Files\Common Files\IRASRIAL.DLL
2007-04-27 20:16 1,682 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-04-27 20:16 88 --sh--r C:\WINDOWS\system32\0C448332F0.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BCC8A4AB-C055-461E-B4B5-1B0EA8647897}]
2007-06-03 18:20 208384 --a------ C:\WINDOWS\system32\confl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2005-02-08 23:06 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2005-02-08 23:02 126976]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe" [2006-10-12 03:10 49263]
"PCSuiteTrayApplication"="D:\PROGRA~1\Nokia\NOKIAP ~1\LAUNCH~1.EXE" [2005-12-13 08:49 217088]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-11 15:10 949376]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41 282624]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2005-04-13 11:51 14156800 C:\WINDOWS\RTHDCPL.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:56 110592 C:\WINDOWS\system32\bthprops.cpl]

C:\Documents and Settings\mand\Start Menu\Programs\Startup\
REALHOUND IP Tune and Lube.LNK - C:\Program Files\REALHOUND IP Client\realhoundiptuneandlube.exe [2006-10-09 11:11:04 303104]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Symantec Fax Starter Edition Port.lnk - D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE [1998-12-23 14:21:54 45568]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^mand^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\mand\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^mand^Start Menu^Programs^Startup^REALHOUND IP Tune and Lube.LNK]
path=C:\Documents and Settings\mand\Start Menu\Programs\Startup\REALHOUND IP Tune and Lube.LNK
backup=C:\WINDOWS\pss\REALHOUND IP Tune and Lube.LNKStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-04-27 11:25 257088 D:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-04-27 09:41 282624 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2006-11-30 21:49 4662776 D:\Program Files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"D:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\Nokia\\Nokia Software Updater\\nsu_ui_client.exe"=
"C:\\Program Files\\Common Files\\Nokia\\Service Layer\\nsl_host_process.exe"=
"C:\\WINDOWS\\PCHEALTH\\HELPCTR\\Binaries\\HelpCtr .exe"=
"D:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\svchost.exe"=
"D:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 Prvflder;Prvflder;C:\WINDOWS\system32\DRIVERS\prvf lder.sys [2006-04-21 08:22]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-10 10:54:18 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-QuickPhrase - D:\Program Files\TypingMaster\quickphrase\quickphrase.exe
HKCU-Run-DLD.EXE - D:\Program Files\Download Direct\DLD.exe
HKLM-Run-C:\WINDOWS\system32\kdvnf.exe - C:\WINDOWS\system32\kdvnf.exe
MSConfigStartUp-Act! Preloader - D:\Program Files\ACT\Act for Windows\ActSage.exe
MSConfigStartUp-Act.Outlook - D:\Program Files\ACT\Act for Windows\Act.Outlook.Service.exe


************************************************** ************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-03 22:53:26
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\sccfg.sys 8192 bytes

scan completed successfully
hidden files: 1

************************************************** ************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\COMMON FILES\LIGHTSCRIBE\LSSRVC.EXE
C:\PROGRAM FILES\ESET\NOD32KRN.EXE
D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\PROGRAM FILES\CANON\CAL\CALMAIN.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
.
************************************************** ************************
.
Completion time: 2008-07-03 22:54:43 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-03 17:24:36

Pre-Run: 4,179,795,968 bytes free
Post-Run: 4,228,128,768 bytes free

157
---------

If this is fixed can I delete the files that I had downloaded. I have 2 files in my C drive with these names- SDfix and Qoobox(dont know what this is). Please let me know if I need to delete anything else.

And once thanks a lotttttttt
mand1 is offline   Reply With Quote


Old 07-03-2008, 07:49 PM   #6 (permalink)
Bronze Member
 
Join Date: Jul 2008
Posts: 25
Default

Forgot to mention one more thing. I dont find findstr, find, sed or swreg in processes
mand1 is offline   Reply With Quote
Old 07-03-2008, 08:01 PM   #7 (permalink)
Diamond Member
 
Respital's Avatar
 
Join Date: Aug 2007
Location: Canada
Age: 15
Posts: 2,646
Default

Please post a fresh HiJackThis log.
Just to make sure you are no longer infected.
__________________
Winner of Photo Tourney: Twilight
/My Rig:/
/Case :/ Antec Sonata III
/Power Supply :/ Antec Earthquake 500W
/Motherboard :/ Gigabyte P35-DSR3
/Processor :/ Intel E6850@3.4Ghz
/Ram :/ Consair 2x 1 Gb 800mhz
/Video Card :/ Zotac 8800 GT
/Monitor:/Samsung T220 w 20 000 : 1 Contrast and 2ms response time
/3DMark06 Score :/ 11730
Respital is offline   Reply With Quote
Old 07-03-2008, 08:16 PM   #8 (permalink)
Diamond Member
 
Punk's Avatar
 
Join Date: Jan 2007
Location: France
Age: 19
Posts: 5,283
Default

Quote:
Originally Posted by mand1 View Post
If this is fixed can I delete the files that I had downloaded. I have 2 files in my C drive with these names- SDfix and Qoobox(dont know what this is). Please let me know if I need to delete anything else.

And once thanks a lotttttttt
We'll get rid of them when we're sure we're done.

I'm currently reading the log to make sure nothing is still on your computer.
__________________
Punk's Website making and registering tutorial!

Rise And Fall, Rage And Grace

The Offspring!

Huck it!
I just want to be who I want to be
guess that's hard for others to see
Punk is offline   Reply With Quote
Old 07-03-2008, 08:23 PM   #9 (permalink)
Bronze Member
 
Join Date: Jul 2008
Posts: 25
Default

This is the new hijack log. I also wanted to let you know that I ran Uniblue spyeraser and I found 3 spyware SearchExe Hijacker(severe) , Adware.BHO.t(high), Trojan-spy.BZub.hv(elevated). Dont know if it is related to the same problem.

Here is the hijack log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:47:18 PM, on 7/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Eset\nod32kui.exe
D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Console Flash v.4.1 - {BCC8A4AB-C055-461E-B4B5-1B0EA8647897} - C:\WINDOWS\system32\confl.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdvnf.exe] C:\WINDOWS\system32\kdvnf.exe
O4 - Startup: REALHOUND IP Tune and Lube.LNK = C:\Program Files\REALHOUND IP Client\realhoundiptuneandlube.exe
O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = D:\Program Files\Microsoft Office\Office\1033\OLFSNT40.EXE
O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .MOV: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7F78793-C4E9-43AC-B077-EC4B720BB791}: NameServer = 218.248.240.23,218.248.240.135
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspn et_state.exe (file missing)
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe

--
End of file - 5549 bytes
mand1 is offline   Reply With Quote
Old 07-03-2008, 08:26 PM   #10 (permalink)
Diamond Member
 
Punk's Avatar
 
Join Date: Jan 2007
Location: France
Age: 19
Posts: 5,283
Default

Your computer has multiple infections, including a backdoor. A backdoor gives intruders complete control of your computer, logs your keystrokes, steal personal information, etc.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall

We can attempt to clean this machine but i can't guarantee that it will be 100% secure afterwards.

Should you have any questions, please feel free to ask.

Please let us know what you have decide

If you wish to continue, do the following:

Download Avenger, and unzip it to your desktop or somewhere you can find it. (Do not run it yet).

Note: This program is for use on Windows XP 32 bit systems only, and must be run from an Administrator account.
  • Open a Notepad file by clicking Start > Run and typing Notepad.exe in the box, click OK.
  • Click Format, and ensure Word Wrap is unchecked.
  • Copy and Paste the text in the box below into Notepad.
  • Now save the file as RemoveFiles.txt in a location where you can find it.

Quote:
Files to delete:
C:\WINDOWS\system32\sex3.ico.tmp
C:\WINDOWS\system32\sex2.ico.tmp
C:\WINDOWS\system32\sex1.ico.tmp
C:\WINDOWS\system32\perfc000.dat
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

Start Avenger by double clicking on Avenger.exe.
  • Check Load script from file:
  • Click on the folder symbol below and to the right, and browse to RemoveFiles.txt.
  • Double click it to enter it into Avenger.
  • Click the green traffic light symbol.
  • You will be asked if you want to execute the script, answer Yes.
  • At this point you may get prompts from your protection systems, allow them please.
  • Avenger will set itself up to run the next time you re-boot, and will prompt you to re-start immediately.
  • Answer Yes, and allow your computer to re-boot.
  • Upon re-boot a command window will briefly appear on screen (this is normal).
  • A Notepad text file will be created C:\avenger.txt.
  • Copy and Paste it into your next post please.

Download and Run DSS

Download Deckard's System Scanner (DSS) to your Desktop. You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<- this one will be minimized.
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your reply.
__________________
Punk's Website making and registering tutorial!

Rise And Fall, Rage And Grace

The Offspring!

Huck it!
I just want to be who I want to be
guess that's hard for others to see

Last edited by Punk; 07-03-2008 at 08:39 PM.
Punk is offline   Reply With Quote
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Help cmoney0954 Computer Security 10 04-30-2008 12:26 PM
Virus Identified alyoob Computer Security 13 03-17-2008 08:22 PM
trojan wont go away even with trojan remover wargamedt Computer Security 5 02-26-2008 08:48 PM
System Alert!! Fake! Re: anti-vermins.com J_D Computer Security 5 01-07-2007 01:36 PM
Plz Plz Plz Help Zeus2005 Computer Cases, Power Supplies and Cooling 2 09-01-2005 03:46 AM


All times are GMT +1. The time now is 02:57 PM.


Powered by: vBulletin Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 ©2009, Crawlability, Inc.