It is currently Tue Sep 01, 2026 1:45 pm


myLog

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

myLog

Postby noby » Sat Jun 19, 2004 4:13 pm

Brad,

i have a comp on my hands that i cleaned out already with
NAV 2004 with latest updates
housecall
I found some virus and or trojans that were cleaned out, but 3 days later the guy complained that he had a lot of virus warnings and so. When i looked into it, i found some more (bugbear)
Everything is cleaned out again, but i suspect maybe that something stayed behind; So if you will do me the favor of having a look into this log ?

most obliged

noby

Here it follows :


Logfile of HijackThis v1.97.7
Scan saved at 17:05:23, on 19/06/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\NotifyPhoneBook.exe
C:\WINDOWS\agfguard.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CONNMN~1.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe
C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\CapMan.exe
C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\ElogErr.exe
C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\BROADC~1.EXE
C:\PROGRA~1\SONYER~1\Mobile\CONNEC~1\SCRFS.exe
C:\PROGRA~1\SONYER~1\Mobile\MOBILE~1\EPMWOR~1.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Documents and Settings\Werner\Mijn documenten\My eBooks\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.planetinternet.be/nl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.isaserver.be;*.isanet.be;info.BBL.be
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IsabelUpgrade] C:\PROGRA~1\Isabel\BIN\ARBOOT.EXE
O4 - HKLM\..\Run: [CloseDNF] C:\WINDOWS\System32\Utility.exe \1008
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: ISDN Guard.lnk = C:\WINDOWS\agfguard.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Phone Connection Monitor.lnk = C:\Program Files\Sony Ericsson\Mobile\audevicemgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Besturing) - http://a840.g.akamai.net/7/840/537/2004 ... scan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 2921643518
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
User avatar
noby
Senior Geek
Senior Geek
 
Posts: 274
Joined: Mon Feb 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

re logfile

Postby badpolarbear » Sat Jun 19, 2004 4:55 pm

A good program to download, install and run is a free 30 day trial of RegVac. It seems to do quite good at removing unwanted and unneeded regisrty files. As for the log I think Brad is the best man for the job.
User avatar
badpolarbear
Executive Geek
Executive Geek
 
Posts: 667
Joined: Mon Feb 23, 2004 1:00 am
Location: Barrys Bay Ontario

Thanks given:0
Thanks received:0
Top

Postby brad » Sat Jun 19, 2004 6:04 pm

Thanks, Folks. RegVac is good. I like System Mechanic a lot better. Bottom line... Run Reg. Cleaners after deleting Trojans and Folder/file so it will clean out the orphans.
So, Noby, what language is this? German?
What I show below is from my searches. Most all the results were in German but most noted that these were HiJackers or "leftovers" from Viri. Please double check to see if they are legit before using my suggestions. (You can always revert back from the HJT backups.)

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

ARBOOT.EXE
Utility.exe
agfguard.exe


Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Koppelingen
O4 - HKLM\..\Run: [IsabelUpgrade] C:\PROGRA~1\Isabel\BIN\ARBOOT.EXE
O4 - HKLM\..\Run: [CloseDNF] C:\WINDOWS\System32\Utility.exe \1008
O4 - Global Startup: ISDN Guard.lnk = C:\WINDOWS\agfguard.exe



Go to Control Panel / Add/Remove Programs and remove the following if they are there:

Isabel


Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\PROGRA~1\Isabel
C:\WINDOWS\System32\Utility.exe
C:\WINDOWS\agfguard.exe

Now, empty your TEMP Folder / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby noby » Sat Jun 19, 2004 6:42 pm

thanks Brad for the very quick answer.
and the language is not German, but you were close : it's Dutch (not doubleDutch)
Now : Isabel is a legit prog (used in maritime circles here)
The R0 entry "koppelingen" you can find under favourites - shortcuts (i think) it's a standard IE folder under favourites so legit also
The others will be treated carefully, and you with admiration and respect !

again, thanks

noby
User avatar
noby
Senior Geek
Senior Geek
 
Posts: 274
Joined: Mon Feb 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Sat Jun 19, 2004 6:49 pm

Thanks.
Please check out this Search on
Hope you get it worked out.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby noby » Sun Jun 20, 2004 12:53 pm

i have followed your suggestions and deleted the "koppelingen" link also.

This is probably not for you, but with your possibilities one never knows :
I have 1 more problem with this recalcitrant one : when i boot, the NAV 2004 protection is turned off. I think this is because it (XP) does not shut down., so the setting probably is not saved. Any suggestions about the shutdown problem?

and many thanks for the above

noby
User avatar
noby
Senior Geek
Senior Geek
 
Posts: 274
Joined: Mon Feb 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 20, 2004 2:32 pm

If I understand you correctly you're saying that you have to manually turn on your NAV? Is there not a setting in Norton to enable? You don't have it unchecked in MSCONFIG do you?
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby noby » Sun Jun 20, 2004 7:08 pm

Well Brad, that is it exactly. I open Norton after booting up, and see the Norton anti virus system status tab says : Protection Not active; still in the system tray it says it is Active. If i set it to Active and reboot, it has returned to Not active, so that is probably why this system keeps getting little things in it's belly. And of course, that it does not shut down (it hangs on the blue screen "Windows is shutting down" forever) does not help much here.

I checked ms config and saw ccApp started and 5 Symantec services, so i think that's ok

ideas on this one??

noby
User avatar
noby
Senior Geek
Senior Geek
 
Posts: 274
Joined: Mon Feb 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Sun Jun 20, 2004 10:42 pm

Check out these possibilites:

This is an excerpt from the above:

Start Norton AntiVirus.
Click Options > Auto-Protect.
Uncheck "Enable Auto-Protect" and "Start Auto-Protect when Windows starts up (recommended)."
Click OK > OK at the next prompt.
Exit Norton AntiVirus.
Restart the computer.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby noby » Mon Jun 21, 2004 8:39 am

User avatar
noby
Senior Geek
Senior Geek
 
Posts: 274
Joined: Mon Feb 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Cactus » Mon Jun 21, 2004 5:23 pm

User avatar
Cactus
Geek Alumni
 
Posts: 1330
Joined: Sat Nov 30, 2002 1:00 am
Location: Somewhere...

Thanks given:0
Thanks received:0
Top

Postby noby » Mon Jun 21, 2004 5:48 pm

User avatar
noby
Senior Geek
Senior Geek
 
Posts: 274
Joined: Mon Feb 09, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron