MyTechSupport.ca :: Your Computer Technical Resource Headquarters! MyTechSupport.ca :: Your Computer Technical Resource Headquarters!
HOME FORUMS RESOURCES & TOOLS ARTICLES ONLINE STORE ABOUT US
Computer Support Forums arrow Internet & Network Support arrow Security & Viruses arrow Topic: startpage.19.j (trojan)
June 03, 2020, 03:34:44 AM
 

Home Forum Rules Help Search Mobile Version Login Register

Welcome, Guest. Please login or register.
Did you miss your activation email?
June 03, 2020, 03:34:44 AM

Login with username, password and session length
 Featured Sites:
News
Article Writers We are looking for quality, informational articles to add to our Computer Articles
Please contact us if you are interested in submitting some....
  0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: startpage.19.j (trojan)  (Read 2523 times)
splttingatms
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 19


Bookmark and Share

View Profile
« on: August 11, 2005, 03:52:58 AM »

PLEASE SUPPLY RELEVANT INFORMATION:
Operating System Version:Windows 2000
Problem Application Name & Version:
Problem Hardware Make & Model:
Error Messages:


I have tried Ad-aware and AVG to remove this trojan but that did not work. Finally I used "SpSeHijfix112" to fix it. Now I want to know for sure this trojan is completely gone. I am posting my Hijack This log.

Logfile of HijackThis v1.99.1
Scan saved at 7:16:47 PM, on 8/10/2005
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
C:\WINNT\System32\taskmgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\wupdmgr.exe
C:\WINNT\explorer.exe
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {BC3D75C0-1697-DF6A-A3D6-1780A7B4BDB2} - C:\WINNT\System32\o8i71s87.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [343763395] D:\Reg\Pentax_Win_GM_12062004.exe /r "D:\Reg\Pentax_Win_GM_12062004.rpd"
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\System32\dcom_9.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

Thanks for your help.
Logged

_-/|=:::this is only the beginning:::=|\-_
sUBs
Global Moderator
Hero Member
*****

Karma: +0/-0
Offline Offline

Posts: 278


Bookmark and Share

View Profile
« Reply #1 on: August 11, 2005, 04:44:25 AM »

Please visit this website - http://virusscan.jotti.org
Submit these file(s) for a comprehensive scan & then post the results back here.

 C:\WINNT\System32\wininet.dll    

If found to be infected, do not attempt to delete it.
Logged

 
splttingatms
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 19


Bookmark and Share

View Profile
« Reply #2 on: August 11, 2005, 08:30:58 PM »

I did as you said and the status of the file is "OK". Nothing was found wrong with it.
Logged

_-/|=:::this is only the beginning:::=|\-_
sUBs
Global Moderator
Hero Member
*****

Karma: +0/-0
Offline Offline

Posts: 278


Bookmark and Share

View Profile
« Reply #3 on: August 11, 2005, 08:57:49 PM »

That's good.

I should have clarified earlier why I had you do that. This entry..

O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe

has been known to infect wininet.dll. The dll is an important file for Internet Explorer. I have had W2K users lose their internet connectivity bcos of this. & that makes repair difficult.

Okay..let's fix your machine


Please save the following instructions in Notepad. I have customed my instructions on the assumption that you have Notepad 'on'. It may lead to some confusion should you choose to do otherwise.

If there's anything that you don't understand, kindly ask your question(s) before proceeding with the fixes. There should not be any open browsers when you are carrying out the procedures below.

IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Please download these additional files/programs.  Do not run them until instructed to do so.
Unless otherwise stated, they should be stored in same directory as the HiJackThis program.  

CleanUp.exe - Install.

KillBox v2.0.0.175.zip

UNPLUG YOUR COMPUTER FOM THE INTERNET WHEN YOU HAVE FINISHED DOWNLOADING


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Close all programs & close all opened Windows/browsers

Uninstall this program using Control panel > Add/Remove program:
PS Guard



Have Hijackthis fix these entries:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: (no name) - {BC3D75C0-1697-DF6A-A3D6-1780A7B4BDB2} - C:\WINNT\System32\o8i71s87.dll
O4 - HKLM\..\Run: [PSGuard] C:\Program Files\PSGuard\PSGuard.exe
O21 - SSODL: DCOM Server - {2C1CD3D7-86AC-4068-93BC-A02304BB8C34} - C:\WINNT\System32\dcom_9.dll



Locate & Delete this folder
C:\Program Files\PSGuard\



Run Cleanup! with the following configuration:
Click Options...
Move the arrow down to Custom CleanUp!
Put a check next to the following options:
Empty Recycle Bins
Delete Cookies
Delete Prefetch files (Windows XP only)
[X]Scan local drives for temporary files (Please uncheck this option)
Cleanup! All Users
 
Click OK
Press the CleanUp! button to start the program. Reboot/logoff when prompted.
* CleanUp! will delete all the files in your temp folders without making a backup



Run KillBox & paste the following locations into KillBox one at a time:
    C:\WINNT\System32\o8i71s87.dll
     C:\WINNT\System32\dcom_9.dll                            

Checkmark the following boxes :
Replace on Reboot
 Use Dummy
 End Explorer Shell While Killing File
 Unregister DLL (If available)]  
     
 Click the RED X button
 Answer YES when asked to confirm file deletion
 Answer NO when prompted to reboot now            
 Proceed with the next file by repeating the above steps.
 Once you get to the last entry, click YES when prompted to reboot.



Upon reboot, perform an online scan with Internet Explorer at Panda ActiveScan

Take note the names and locations of any file it detects but fails to clean.
* Turn off the real time scanner of any existing antivirus program while performing the online scan



In your next post, please include fresh logs from:
    HiJackThis
     Online scan
 
Please provide details of any problems you encountered whilst performing the above steps & update us on how the computer behaves now    




« Last Edit: August 11, 2005, 08:58:36 PM by sUBs » Logged

 
splttingatms
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 19


Bookmark and Share

View Profile
« Reply #4 on: August 12, 2005, 05:22:37 AM »

I could not find the program "PS Guard" under the Add/Remove program, but I didn't find the file in "C:\Program Files\PSGuard\". When I opened the Add/Remove program, I got a message saying "explorer.exe has generated errors and will be closed by Windows. You will need to restart the program. An error log is being created." then the background changes  removing the start menu and then the start menu pops back up.
Logged

_-/|=:::this is only the beginning:::=|\-_
sUBs
Global Moderator
Hero Member
*****

Karma: +0/-0
Offline Offline

Posts: 278


Bookmark and Share

View Profile
« Reply #5 on: August 12, 2005, 03:30:48 PM »

Please complete the rest of the fix & show me the report from the Panda scan.

I would also require a fresh Hijackthis log.

Thanks
Logged

 
splttingatms
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 19


Bookmark and Share

View Profile
« Reply #6 on: August 13, 2005, 02:32:35 AM »

This is the new Hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 7:34:05 PM, on 8/12/2005
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
C:\WINNT\explorer.exe
C:\Program Files\Hijack This\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [343763395] D:\Reg\Pentax_Win_GM_12062004.exe /r "D:\Reg\Pentax_Win_GM_12062004.rpd"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

------------------------------------------------------------------------------------

This is the Panda scan.


Incident                      Status                        Location                                                                                                                                                                                                                                                        

Adware:adware/psguard         No disinfected                C:\WINNT\SYSTEM32\intell32.exe                                                                                                                                                                                                                                  
Adware:adware/cws.homesearchasisstantNo disinfected                Windows Registry                                                                                                                                                                                                                                                
Adware:Adware/Troyanov        No disinfected                C:\Documents and Settings\chiasco000\Application Data\Microsoft\dcom_8.dll                                                                                                                                                                                      
Virus:Trj/Downloader.DOY      Disinfected                   C:\Program Files\Hijack This\backups\backup-20050812-112514-213.dll                                                                                                                                                                                            
Adware:Adware/StartPage.AES   No disinfected                C:\q626464.exe                                                                                                                                                                                                                                                  
Adware:Adware/Troyanov        No disinfected                C:\WINNT\system32\dcom_8.dll                                                                                                                                                                                                                                    
Virus:Trj/Qhost.gen           Disinfected                   C:\WINNT\system32\drivers\etc\hosts                                                                                                                                                                                                                            
Adware:Adware/PsGuard         No disinfected                C:\WINNT\system32\intell32.exe                                                                                                                                                                                                                                  
Logged

_-/|=:::this is only the beginning:::=|\-_
sUBs
Global Moderator
Hero Member
*****

Karma: +0/-0
Offline Offline

Posts: 278


Bookmark and Share

View Profile
« Reply #7 on: August 13, 2005, 04:02:10 AM »

Here's what you need to do to get cleaned.

Please save the following instructions in Notepad. I have customed my instructions on the assumption that you are using Notepad. It may lead to some confusion should you choose to do otherwise.

If there's anything that you don't understand, kindly ask your question(s) before proceeding with the fixes. There should not be any open browsers when you are carrying out the procedures below.

IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Please download these additional files/programs.  Do not run them unless instructed to do so.
Unless otherwise stated, they should be stored in same directory as the HiJackThis program.

CleanUp! - Install

Hoster - Save to desktop.      

DelO15Domains.inf - Right click & choose "Save As..." DelO15Domains.inf.

Ewido Security Suite - Install &  Update it's database but do not run it yet.


= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

REBOOT TO SAFE MODE
 Restart the computer. The computer begins processing a set of instructions known as BIOS.
 As soon as the BIOS has finished loading, begin tapping the F8 key on your keyboard.
 Continue to do so until the 'Windows Advanced Options' menu appears.
 Using the arrow keys on the keyboard, scroll to and select the menu item - Safe Mode.

= = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = = =

Enable the viewing of Hidden files
From Windows Explorer, go to Tools>Folder Options>View tab.
 Enable the option for `Show hidden files and folder
Logged

 
splttingatms
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 19


Bookmark and Share

View Profile
« Reply #8 on: August 13, 2005, 06:45:20 AM »

I noticed that the restart of the computer took a noticably lot longer than before. Is this normal?

---------------------------------------------------------------------------------------
Here is the fresh HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 11:40:52 PM, on 8/12/2005
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
C:\WINNT\System32\taskmgr.exe
C:\Program Files\Hijack This\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [343763395] D:\Reg\Pentax_Win_GM_12062004.exe /r "D:\Reg\Pentax_Win_GM_12062004.rpd"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Wireless-B Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe

---------------------------------------------------------------------------------------

This is the Antispyware log.

      Started Scanning
      Internet Cookies
      Programs in Memory
      Windows Registry
         Found '' in 'SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinMX'
      Internet URL Shortcuts
      Files and Directories
         Found '' in 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX'
         Found '' in 'C:\Program Files\WinMX'
         Found 'errcatch.exe' in 'C:\Program Files\WinMX'
         Found 'uninstall.exe' in 'C:\Program Files\WinMX'
         Found 'WinMX.exe' in 'C:\Program Files\WinMX'
         Found 'winmx353.exe' in 'C:\Program Files'
      Finished Scanning
      Started Backup
      Finished Backup
      Started Cleaning
         Checking for 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX' in shortcut areas.
         Checking for 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX' in startup areas.
         Cleaning 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX'
         Checking for 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\WinMX.lnk' in shortcut areas.
         Checking for 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\WinMX.lnk' in startup areas.
         Cleaning 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\WinMX.lnk'
         Checking for 'C:\Program Files\WinMX' in shortcut areas.
         Checking for 'C:\Program Files\WinMX' in startup areas.
         Cleaning 'C:\Program Files\WinMX'
         Checking for 'C:\Program Files\WinMX\colors.dat' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\colors.dat' in startup areas.
         Cleaning 'C:\Program Files\WinMX\colors.dat'
         Checking for 'C:\Program Files\WinMX\errcatch.exe' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\errcatch.exe' in startup areas.
         Cleaning 'C:\Program Files\WinMX\errcatch.exe'
         Checking for 'C:\Program Files\WinMX\library.dat' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\library.dat' in startup areas.
         Cleaning 'C:\Program Files\WinMX\library.dat'
         Checking for 'C:\Program Files\WinMX\license.txt' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\license.txt' in startup areas.
         Cleaning 'C:\Program Files\WinMX\license.txt'
         Checking for 'C:\Program Files\WinMX\settings.dat' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\settings.dat' in startup areas.
         Cleaning 'C:\Program Files\WinMX\settings.dat'
         Checking for 'C:\Program Files\WinMX\uninstall.exe' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\uninstall.exe' in startup areas.
         Cleaning 'C:\Program Files\WinMX\uninstall.exe'
         Checking for 'C:\Program Files\WinMX\WinMX.exe' in shortcut areas.
         Found 'WinMX.lnk' in 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\'
         Found 'WinMX.lnk' in 'C:\Documents and Settings\chiasco000\Desktop\'
      [SCANMODS] The file 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\WinMX.lnk' was not found. Most likely already cleaned by another scanner module.
         Checking for 'C:\Program Files\WinMX\WinMX.exe' in startup areas.
         Cleaning 'C:\Program Files\WinMX\WinMX.exe'
         Checking for 'C:\Program Files\WinMX\wpnpchannelcmds.txt' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\wpnpchannelcmds.txt' in startup areas.
         Cleaning 'C:\Program Files\WinMX\wpnpchannelcmds.txt'
         Checking for 'C:\Program Files\WinMX\errcatch.exe' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\errcatch.exe' in startup areas.
         Cleaning 'C:\Program Files\WinMX\errcatch.exe'
      [SCANMODS] The file 'C:\Program Files\WinMX\errcatch.exe' was not found. Most likely already cleaned by another scanner module.
         Checking for 'C:\Program Files\WinMX\uninstall.exe' in shortcut areas.
         Checking for 'C:\Program Files\WinMX\uninstall.exe' in startup areas.
         Cleaning 'C:\Program Files\WinMX\uninstall.exe'
      [SCANMODS] The file 'C:\Program Files\WinMX\uninstall.exe' was not found. Most likely already cleaned by another scanner module.
         Checking for 'C:\Program Files\WinMX\WinMX.exe' in shortcut areas.
         Found 'WinMX.lnk' in 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\'
         Found 'WinMX.lnk' in 'C:\Documents and Settings\chiasco000\Desktop\'
      [SCANMODS] The file 'C:\Documents and Settings\chiasco000\Start Menu\Programs\WinMX\WinMX.lnk' was not found. Most likely already cleaned by another scanner module.
      [SCANMODS] The file 'C:\Documents and Settings\chiasco000\Desktop\WinMX.lnk' was not found. Most likely already cleaned by another scanner module.
         Checking for 'C:\Program Files\WinMX\WinMX.exe' in startup areas.
         Cleaning 'C:\Program Files\WinMX\WinMX.exe'
      [SCANMODS] The file 'C:\Program Files\WinMX\WinMX.exe' was not found. Most likely already cleaned by another scanner module.
         Checking for 'C:\Program Files\winmx353.exe' in shortcut areas.
         Checking for 'C:\Program Files\winmx353.exe' in startup areas.
         Cleaning 'C:\Program Files\winmx353.exe'
      Finished Cleaning
---------------------------------------------------------------------------------------

This is the Ewido's log

---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         11:00:50 PM, 8/12/2005
 + Report-Checksum:      AECDBA62

 + Scan result:

   HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
   HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
   C:\Program Files\WinAce\winace.exe -> Heuristic.Win32.AVKiller : Cleaned with backup


::Report End
Logged

_-/|=:::this is only the beginning:::=|\-_
sUBs
Global Moderator
Hero Member
*****

Karma: +0/-0
Offline Offline

Posts: 278


Bookmark and Share

View Profile
« Reply #9 on: August 13, 2005, 06:53:08 AM »

Your start-up times should improve after a few reboots. If it doesn't do so, pls come back & tell me about it.

Your system is clean  

I like to ask a favor from you. Please update Windows to Service Pack 4 (SP4). With your current configuration, you're just too vulnerable & may be re-infected within weeks.

Now that your system is clean, please follow these simple steps in order to keep your computer clean and secure:
  1. Make your Internet Explorer more secure -  This can be done by following these simple instructions:

    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
        Change the Download unsigned ActiveX controls to Disable
        Change the Initialize and script ActiveX controls not marked as safe to Disable
        Change the Installation of desktop items to Prompt
        Change the Launching programs and files in an IFRAME to Prompt
        Change the Navigate sub-frames across different domains to Prompt
    5. When all these settings have been made, click on the OK button.
    6. If it prompts you as to whether or not you want to save the settings, press the Yes button.
    7. Next press the Apply button and then the OK to exit the Internet Properties page.


  2. Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine.  This alone can save you a lot of trouble with malware in the future.

    See this link for a listing of some online & their stand-alone antivirus programs:
    Virus, Spyware, and Malware Protection and Removal Resources


  3. Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish).  If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


  4. Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.  Without a firewall your computer is succeptible to being hacked and taken over.  I am very serious about this and see it happen almost every day with my clients.  Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Understanding and Using Firewalls


  5. Visit Microsoft's Windows Update Site Frequently - It is important that you visit windowsupdate.com regularly.  This will ensure your computer has always the latest security updates available installed on your computer.  If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


  6. Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.  This will provide realtime spyware & hijacker protection on your computer alongside your virus protection.  You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers


  7. Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware,  & Hijackers from Your Computer

  8. Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware


  9. Update all these programs regularly - Make sure you update all the programs I have listed regularly.  Without regular updates you WILL NOT be protected when new malicious programs are released.


  10. Winpatrol -  Download and install the free version of Winpatrol.

    A tutorial for this product is located here  Using Winpatrol to protect your computer from malicious software


  11. IE/Spyad - IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system.  It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.


  12. MVPS Hosts file - The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc.  Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer


  13. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program!  (AOL, Yahoo, ICQ, IRC, MSN)


  14. Weather Watcher - Free taskbar weather program that is free, malware free, and resource light.


  15. Firefox - Use this alternate browser. Whilst Internet Explorer is not a bad browser, almost every exploit crafted is targeted to take advantage of an IE weakness.


  16. Sun's Java - It's much more secure than Microsoft's Java Virtual Machine.


  17. Google Toolbar - Get the free google toolbar to help stop pop up windows.

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein

Follow this list and your potential for being infected again will reduce dramatically. Your system will be optimised against future threats.

It's okay to delete the Hijack This folder in a couple weeks if everything is working okay.
Have a safe & happy computing day.  

Please respond to this thread one more time so we can mark this thread as resolved.
Logged

 
splttingatms
Jr. Member
**

Karma: +0/-0
Offline Offline

Gender: Male
Posts: 19


Bookmark and Share

View Profile
« Reply #10 on: August 13, 2005, 06:59:29 AM »

THANK YOU, I liked your easy to read instructions and it didn't take long for you to respond. I will definitly come here for help next time. Thanks again.
Logged

_-/|=:::this is only the beginning:::=|\-_
Pages: [1] Go Up Print 
 
Jump to:  

Powered by MySQL Powered by PHP

Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS!

Disclaimer
This site is NOT responsible for any damage that the information on this site may cause to your system. Everything you try, whether inspired by the response given from this site or not, is entirely at your own risk. All product names and company names used herein are for identification purpose only and may be trademarks or registered trademarks of their respective owners. We are in no way affiliated or representing any of the companies on this site unless specified.
Back to Top
Stop Spam Harvesters, Join Project Honey Pot Fight Back Against Spammers! Get Firefox! Get Thunderbird! View Sylvain Amyots profile on LinkedIn
Back to Top
Google visited last this page April 06, 2017, 12:21:10 AM