I've been lurking here for a few days trying to resolve my virus issue. Prior to reading this forum I had been using the Spy-bot and Adware programs. I then tried the free version of AVG and after it scans it keeps showing a virus called 'ibbaibb.dll' and its backup file. Looked at the info and says it a BHO file...this makes sense as my internet has been very very slow.
I have, however, since tried CWshredder...didn't seem to work and also Hijack This. Please see my HJT log below. HJT labels describes it as 'Trojan horse Clicker.FMZ' I've ran HJT scans and then ran them again in Safe Mode with networking...then ran Kerpasky but that did not seem to help with this virus. Also tried a Trend Micro virus scanner and it showed a virus in: C:\ProgramFiles\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (I'm thinking the reason I cannot manually delete the ibbaibb.dll file is that it might be reverting back to .jar file)
What can I do to manually delete this? Nothing seems to work at this moment. Thank you!
Logfile of HijackThis v1.99.1
Scan saved at 11:03:19 PM, on 5/10/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\devldr32.exe
C:\Documents and Settings\Brian\My Documents\Unzipped\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://education.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://scripts.affiliatefuture.com/...469&programmeID=1675&mediaID=0&tracking=&url=
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: (no name) - {1BB26A5E-C72F-4423-B9B5-E8A3EF6212FE} - c:\windows\system32\ibbaibb.dll
O2 - BHO: MS Explorer - {9A5C9584-DE98-310B-21A1-899F87184987} - C:\WINDOWS\system\wmdcst32.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [*pcnut] C:\WINDOWS\security\Database\pcnut.exe
O4 - HKLM\..\Run: [*tasklog] C:\WINDOWS\Driver Cache\tasklog.exe
O4 - HKLM\..\Run: [*mfcdb] C:\WINDOWS\Fonts\mfcdb.exe
O4 - HKLM\..\Run: [*taskvga] C:\WINDOWS\java\Packages\taskvga.exe
O4 - HKLM\..\Run: [*inetsvr] C:\WINDOWS\Cursors\inetsvr.exe
O4 - HKLM\..\Run: [*wavedisk] C:\WINDOWS\Fonts\wavedisk.exe
O4 - HKLM\..\Run: [*coms] C:\WINDOWS\Web\PRINTERS\coms.exe
O4 - HKLM\..\Run: [*infoplay] C:\WINDOWS\Config\infoplay.exe
O4 - HKLM\..\Run: [*comcmd] C:\WINDOWS\system32\1054\comcmd.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.insightbb.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O20 - Winlogon Notify: ecemjftf - C:\WINDOWS\SYSTEM32\ibbaibb.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
I have, however, since tried CWshredder...didn't seem to work and also Hijack This. Please see my HJT log below. HJT labels describes it as 'Trojan horse Clicker.FMZ' I've ran HJT scans and then ran them again in Safe Mode with networking...then ran Kerpasky but that did not seem to help with this virus. Also tried a Trend Micro virus scanner and it showed a virus in: C:\ProgramFiles\MyWebSearch\bar\1.bin\M3NTSTBR.JAR (I'm thinking the reason I cannot manually delete the ibbaibb.dll file is that it might be reverting back to .jar file)
What can I do to manually delete this? Nothing seems to work at this moment. Thank you!
Logfile of HijackThis v1.99.1
Scan saved at 11:03:19 PM, on 5/10/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\devldr32.exe
C:\Documents and Settings\Brian\My Documents\Unzipped\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.insightbb.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://education.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://scripts.affiliatefuture.com/...469&programmeID=1675&mediaID=0&tracking=&url=
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: (no name) - {1BB26A5E-C72F-4423-B9B5-E8A3EF6212FE} - c:\windows\system32\ibbaibb.dll
O2 - BHO: MS Explorer - {9A5C9584-DE98-310B-21A1-899F87184987} - C:\WINDOWS\system\wmdcst32.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [*pcnut] C:\WINDOWS\security\Database\pcnut.exe
O4 - HKLM\..\Run: [*tasklog] C:\WINDOWS\Driver Cache\tasklog.exe
O4 - HKLM\..\Run: [*mfcdb] C:\WINDOWS\Fonts\mfcdb.exe
O4 - HKLM\..\Run: [*taskvga] C:\WINDOWS\java\Packages\taskvga.exe
O4 - HKLM\..\Run: [*inetsvr] C:\WINDOWS\Cursors\inetsvr.exe
O4 - HKLM\..\Run: [*wavedisk] C:\WINDOWS\Fonts\wavedisk.exe
O4 - HKLM\..\Run: [*coms] C:\WINDOWS\Web\PRINTERS\coms.exe
O4 - HKLM\..\Run: [*infoplay] C:\WINDOWS\Config\infoplay.exe
O4 - HKLM\..\Run: [*comcmd] C:\WINDOWS\system32\1054\comcmd.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.insightbb.com
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup152.cab
O20 - Winlogon Notify: ecemjftf - C:\WINDOWS\SYSTEM32\ibbaibb.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe