It is currently Tue Sep 01, 2026 3:07 pm


PLEASE HELP - PC INVASION!! See HijackThis Log below

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

PLEASE HELP - PC INVASION!! See HijackThis Log below

Postby ewok » Sat Jun 26, 2004 10:03 pm

PLEASE HELP ME, my PC has been invaded. The homepage is being reset and every time I go online more exe files are being downloaded. Have run Spybot (each time it finds 5 DSO Exploits despite fixing them) and TrojanHunter (has found 5 possible trojan files plus RECYCLER file in C Drive). When I search for RECYCLER file in explorer it cannot be found. WINDOWS and APPLICATION DATA files have become hidden and only accessible through a windows search. This all must have something to do with the atlzk.exe file which keeps appearing in Task Manager but can find no reference to this online.

HijackThis Log below, please look through it and let me know what to do - many thanks to anybody who is able to help me.

Logfile of HijackThis v1.97.7
Scan saved at 21:46:50, on 26/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\WinZip\winzip32.exe
C:\DOCUME~1\Becky\LOCALS~1\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ypmmk.dll/sp.html#35759
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ypmmk.dll/index.html#35759
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/e ... efault.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ypmmk.dll/index.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ypmmk.dll/sp.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ypmmk.dll/index.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ypmmk.dll/sp.html#35759
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {9DCBB1DC-3AC3-F6EF-3D33-03958BE2C94C} - C:\WINDOWS\crln32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [WinInit] Win86.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKLM\..\Run: [msjv.exe] C:\WINDOWS\system32\msjv.exe
O4 - HKLM\..\Run: [netbv32.exe] C:\WINDOWS\system32\netbv32.exe
O4 - HKLM\..\RunOnce: [javazw32.exe] C:\WINDOWS\javazw32.exe
O4 - HKLM\..\RunOnce: [atlgg32.exe] C:\WINDOWS\atlgg32.exe
O4 - HKLM\..\RunOnce: [ievm.exe] C:\WINDOWS\system32\ievm.exe
O4 - HKLM\..\RunOnce: [crcm32.exe] C:\WINDOWS\crcm32.exe
O4 - HKLM\..\RunOnce: [netdl.exe] C:\WINDOWS\system32\netdl.exe
O4 - HKLM\..\RunOnce: [d3en32.exe] C:\WINDOWS\system32\d3en32.exe
O4 - HKLM\..\RunOnce: [atlxn.exe] C:\WINDOWS\system32\atlxn.exe
O4 - HKLM\..\RunOnce: [sysrp32.exe] C:\WINDOWS\sysrp32.exe
O4 - HKLM\..\RunOnce: [atlzk.exe] C:\WINDOWS\atlzk.exe
O4 - HKLM\..\RunOnce: [crgx32.exe] C:\WINDOWS\system32\crgx32.exe
O4 - HKLM\..\RunOnce: [winmr.exe] C:\WINDOWS\winmr.exe
O4 - HKLM\..\RunOnce: [addxm32.exe] C:\WINDOWS\system32\addxm32.exe
O4 - HKLM\..\RunOnce: [mfcnd32.exe] C:\WINDOWS\system32\mfcnd32.exe
O4 - HKLM\..\RunOnce: [mfclt32.exe] C:\WINDOWS\mfclt32.exe
O4 - HKLM\..\RunOnce: [crbr32.exe] C:\WINDOWS\crbr32.exe
O4 - HKLM\..\RunOnce: [apiht.exe] C:\WINDOWS\apiht.exe
O4 - HKLM\..\RunOnce: [atlzs32.exe] C:\WINDOWS\atlzs32.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 2626736111
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/sh ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E872E10-3F80-424B-BDE9-0360F78F7331}: NameServer = 194.168.4.100 194.168.8.100
User avatar
ewok
Newbie
Newbie
 
Posts: 3
Joined: Sun Jun 27, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

HELP!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

Postby ewok » Sun Jun 27, 2004 8:57 am

Would somebody please help me - this problem is getting worse and worse....14 views of my problem and no reply!
User avatar
ewok
Newbie
Newbie
 
Posts: 3
Joined: Sun Jun 27, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 27, 2004 9:37 am

Sorry....... busy day.
Please do this first:
**(Always create a Folder for HiJackThis anywhere but your Temp/Temporary Internet Folders. This is where it will save the backup files needed if there's a problem.)**

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

Win86.exe
msjv.exe
netbv32.exe
javazw32.exe
atlgg32.exe
ievm.exe
crcm32.exe
netdl.exe
d3en32.exe
atlxn.exe
sysrp32.exe
atlzk.exe
crgx32.exe
winmr.exe
addxm32.exe
mfcnd32.exe
mfclt32.exe
crbr32.exe
apiht.exe
atlzs32.exe


Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ypmmk.dll/sp.html#35759
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://ypmmk.dll/index.html#35759
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.euro.dell.com/countries/uk/e ... efault.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://ypmmk.dll/index.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\ypmmk.dll/sp.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://ypmmk.dll/index.html#35759
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\ypmmk.dll/sp.html#35759
O2 - BHO: (no name) - {9DCBB1DC-3AC3-F6EF-3D33-03958BE2C94C} - C:\WINDOWS\crln32.dll
O4 - HKLM\..\Run: [WinInit] Win86.exe
O4 - HKLM\..\Run: [msjv.exe] C:\WINDOWS\system32\msjv.exe
O4 - HKLM\..\Run: [netbv32.exe] C:\WINDOWS\system32\netbv32.exe
O4 - HKLM\..\RunOnce: [javazw32.exe] C:\WINDOWS\javazw32.exe
O4 - HKLM\..\RunOnce: [atlgg32.exe] C:\WINDOWS\atlgg32.exe
O4 - HKLM\..\RunOnce: [ievm.exe] C:\WINDOWS\system32\ievm.exe
O4 - HKLM\..\RunOnce: [crcm32.exe] C:\WINDOWS\crcm32.exe
O4 - HKLM\..\RunOnce: [netdl.exe] C:\WINDOWS\system32\netdl.exe
O4 - HKLM\..\RunOnce: [d3en32.exe] C:\WINDOWS\system32\d3en32.exe
O4 - HKLM\..\RunOnce: [atlxn.exe] C:\WINDOWS\system32\atlxn.exe
O4 - HKLM\..\RunOnce: [sysrp32.exe] C:\WINDOWS\sysrp32.exe
O4 - HKLM\..\RunOnce: [atlzk.exe] C:\WINDOWS\atlzk.exe
O4 - HKLM\..\RunOnce: [crgx32.exe] C:\WINDOWS\system32\crgx32.exe
O4 - HKLM\..\RunOnce: [winmr.exe] C:\WINDOWS\winmr.exe
O4 - HKLM\..\RunOnce: [addxm32.exe] C:\WINDOWS\system32\addxm32.exe
O4 - HKLM\..\RunOnce: [mfcnd32.exe] C:\WINDOWS\system32\mfcnd32.exe
O4 - HKLM\..\RunOnce: [mfclt32.exe] C:\WINDOWS\mfclt32.exe
O4 - HKLM\..\RunOnce: [crbr32.exe] C:\WINDOWS\crbr32.exe
O4 - HKLM\..\RunOnce: [apiht.exe] C:\WINDOWS\apiht.exe
O4 - HKLM\..\RunOnce: [atlzs32.exe] C:\WINDOWS\atlzs32.exe

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\WINDOWS\Win86.exe
C:\WINDOWS\system32\msjv.exe
C:\WINDOWS\system32\netbv32.exe
C:\WINDOWS\javazw32.exe
C:\WINDOWS\atlgg32.exe
C:\WINDOWS\system32\ievm.exe
C:\WINDOWS\crcm32.exe
C:\WINDOWS\system32\netdl.exe
C:\WINDOWS\system32\d3en32.exe
C:\WINDOWS\system32\atlxn.exe
C:\WINDOWS\sysrp32.exe
C:\WINDOWS\atlzk.exe
C:\WINDOWS\system32\crgx32.exe
C:\WINDOWS\winmr.exe
C:\WINDOWS\system32\addxm32.exe
C:\WINDOWS\system32\mfcnd32.exe
C:\WINDOWS\mfclt32.exe
C:\WINDOWS\crbr32.exe
C:\WINDOWS\apiht.exe
C:\WINDOWS\atlzs32.exe
C:\WINDOWS\system32\ypmmk.dll

Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby ewok » Sun Jun 27, 2004 12:52 pm

Many thanks for your reply and advice. I followed your instructions and deleted all suspicious files I could find today, and since coming back online everything appears OK.

An updated HijackThis log is below - please reply if you can see any further possible problems. I will repost if anything else happens. Thanks again for your help!

Logfile of HijackThis v1.97.7
Scan saved at 12:46:01, on 27/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\alg.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spyware Doctor\spydoctor.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINDOWS\System32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Becky\Desktop\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\spydoctor.exe" /Q
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: Real.com (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 2626736111
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/sh ... wflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7E872E10-3F80-424B-BDE9-0360F78F7331}: NameServer = 194.168.4.100 194.168.8.100
User avatar
ewok
Newbie
Newbie
 
Posts: 3
Joined: Sun Jun 27, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron