It is currently Tue Sep 01, 2026 3:04 pm


Post-removal problems...

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Post-removal problems...

Postby iorek64 » Tue Jun 29, 2004 7:01 pm

I posted earlier and i followed your instructions on removing the trojan, and it worked but my computer's been acting wierd. It's freezing a lot more (probably due to my lack of ram) but when it starts up, in mid-startup actually, it restarts by itself. I have no idea what's going on. And even when I shutdown the computer normally, scandisk keeps turning on and tells me that i didn't shut it down properly. Any help is appreciated. And here's my Hijack This logfile:

Logfile of HijackThis v1.97.7
Scan saved at 1:58:22 PM, on 6/29/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\qttask.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe
C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe
C:\WINDOWS\System32\taskswitch.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Trend Micro\PC-cillin 2000\Tmntsrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Idichandy John\Desktop\PTI\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wowway.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.sony.com/vaiopeople
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\system32\qttask.exe
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\Pop3trap.exe"
O4 - HKLM\..\Run: [WebTrapNT.exe] "C:\Program Files\Trend Micro\PC-cillin 2000\WebTrapNT.exe"
O4 - HKLM\..\Run: [SENTRY] C:\WINDOWS\SENTRY.exe
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\System32\taskswitch.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [LoadHome] C:\Windows\System\MSIK673.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.EXE 1
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: WeatherBug (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: Yahoo! Tic-Tac-Toe - http://download.games.yahoo.com/games/c ... /ft3_x.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - http://components.metastream.com/MTSIns ... tream3.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://anu.popcap.com/games/popcaploader_v5.cab


Perhaps it didn't work? I dunno. I also noticed that it says that a file is missing. Whatever it is, i need some help. Thanks in advance.
iorek64
Geek in Training
Geek in Training
 
Posts: 28
Joined: Fri Jun 04, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby Geekgirl » Tue Jun 29, 2004 7:08 pm

After your log is read and you follow brad's instructions I advise you to go to Windows Update.
Geekgirl
Geek Alumni
 
Posts: 1214
Joined: Mon Apr 12, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Tue Jun 29, 2004 7:26 pm

Most all of this was in your first post.

This is a must:
After you've finished fixing this problem I strongly recommend that you visit the and download the Critical Updates.

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

MSIK673.exe
alchem.exe
Weather.EXE


Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.)
(This would also include the “GoBack” Program if it is installed.)
Close all other open Windows and have HiJackThis Fix:


O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll (file missing)
O4 - HKLM\..\Run: [LoadHome] C:\Windows\System\MSIK673.exe
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKCU\..\Run: [Weather] C:\Program Files\AWS\WeatherBug\Weather.EXE 1
O9 - Extra button: WeatherBug (HKCU)


Go to Control Panel / Add/Remove Programs and remove the following if they are there:

WeatherBug

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab) (You may have to boot to "Safe Mode" in order to delete some Files/Folders)

C:\Windows\System\MSIK673.exe
C:\WINDOWS\alchem.exe
C:\Program Files\AWS\WeatherBug

Now, empty all your TEMP Folders (WinXp has up to 4 of them) / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby iorek64 » Tue Jun 29, 2004 8:50 pm

I did everything you said except the update thing because i need some help finding the temp folders; i'm not sure if emptying the temporary internet files folder through the actual browser itself is enough. Also, i couldn't find msik673 eventhough it was present as a BHO in the hijack this log file.
iorek64
Geek in Training
Geek in Training
 
Posts: 28
Joined: Fri Jun 04, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Tue Jun 29, 2004 10:16 pm

Go to Windows Explorer / Tools / “Folder Options” / View Tab / and set “Show all Files” and uncheck “Hide System Files”.

C:\Documents and Settings\Username\Local Settings\Temp
C:\Documents and Settings\Administrator\Local Settings\Temp
C:\WINDOWS\Temp

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 1 guest

cron