It is currently Tue Sep 01, 2026 1:13 pm


Help Please(My Computer is also infected by "www.find-o

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Help Please(My Computer is also infected by "www.find-o

Postby Kagomelee » Fri Jun 18, 2004 4:48 am

Help,please.
My Computer is also infected by "www.find-online.net". But the symbol is quite different.
Here is the log from Hijackthis:

Logfile of HijackThis v1.97.7
Scan saved at 11:43:46, on 2004-6-18
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\rising\rav\CCenter.exe
C:\Program Files\rising\rav\RavMonD.exe
C:\WINDOWS\System32\khooker.exe
C:\Program Files\rising\rav\RavTimer.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SkyNet\FireWall\PFW.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\System32\svchost.exe
D:\UltraFXP\UltraFxp.exe
C:\Program Files\MyIE2\MyIE.exe
C:\Program Files\FlashGet\flashget.exe
D:\Spybot - Search & Destroy\SpybotSD.exe
D:\HijackThis\HijackThis.exe

O2 - BHO: (no name) - {4EF1324B-5DD9-4E71-A2C2-15E0B4D016AE} - C:\PROGRA~1\NETCAM~1\brsclick.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [internat.exe] internat.exe
O4 - HKLM\..\Run: [RavTimer] C:\PROGRA~1\rising\Rav\RavTimer.exe
O4 - HKLM\..\Run: [ccenter] C:\Program Files\rising\Rav\CCenter.exe
O4 - HKLM\..\Run: [RavMon] C:\PROGRA~1\rising\Rav\RavMon.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] DSLAGENT.EXE USB
O4 - HKLM\..\Run: [IMSCMig] C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /Preload
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM32\MDM.EXE
O4 - HKLM\..\RunServices: [ccenter] C:\Program Files\rising\Rav\CCenter.exe
O4 - HKLM\..\RunServices: [RavMon] C:\PROGRA~1\rising\Rav\RavMon.exe /AUTO
O4 - HKCU\..\Run: [ziphelp] C:\WINDOWS\ziphelp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download all by NetCamels - C:\PROGRA~1\NETCAM~1\nc_all.htm
O8 - Extra context menu item: Download by NetCamels - C:\PROGRA~1\NETCAM~1\nc_link.htm
O8 - Extra context menu item: Download using Download &Express - file://C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: 使用网际快车下载 - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: 使用网际快车下载全部链接 - C:\Program Files\FlashGet\jc_all.htm
O9 - Extra button: UCmore Info (HKLM)
O9 - Extra 'Tools' menuitem: UCmore help (HKLM)
O9 - Extra button: ICQ Lite (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O9 - Extra button: QQ (HKLM)
O9 - Extra button: FlashGet (HKLM)
O9 - Extra 'Tools' menuitem: &FlashGet (HKLM)
O16 - DPF: {5FA10527-DF55-11D5-BC6D-006097C36D29} (Afx3 Control) - http://photos.gznet.com/upload/afx3.cab
O16 - DPF: {607DF741-7D0A-11D4-9EDC-005004189684} - http://www.ucmore.com/download/UCmoreIEx.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... 3008912037
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/mail/ymmapi.cab
O16 - DPF: {CCB49BC3-E872-4741-BF40-67AE5FBD1753} (IMC Control) - http://202.107.236.180/talk.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {FC87A650-207D-4392-A6A1-82ADBC56FA64} - http://xbs.mtree.com/mt/dialers/fc/MultiDistFC.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{3719FA81-A06D-4C6E-9696-449884228F01}: NameServer = 202.96.134.133,202.96.134.188
O17 - HKLM\System\CCS\Services\Tcpip\..\{8A7EB2A9-856B-48A8-99DD-5A48EE418BA3}: NameServer = 202.98.198.168 202.98.192.68

The destruction caused by the webside is the same, but I can not find the webside in the log file derived from Hijackthis. Two files named NTUSER, which can also be found in the above log, could not be deleted.

Thanks very much! Kagomelee
Kagomelee
Newbie
Newbie
 
Posts: 3
Joined: Fri Jun 18, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Fri Jun 18, 2004 9:32 am

After you've finished fixing this problem I strongly recommend that you visit the and download the Critical Updates.

Try running HJT in "Safe Mode" to fix the following:

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

ziphelp.exe

Turn off System Restore. (Turn it back on after this is repaired and you've rebooted.) Close all other open Windows and have HiJackThis Fix:

O2 - BHO: (no name) - {4EF1324B-5DD9-4E71-A2C2-15E0B4D016AE} - C:\PROGRA~1\NETCAM~1\brsclick.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O4 - HKCU\..\Run: [ziphelp] C:\WINDOWS\ziphelp.exe
O4 - Startup: NTUSER.DAT
O4 - Startup: ntuser.dat.LOG
O4 - Startup: ntuser.ini
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

Now, empty your TEMP Folder / Temporary Internet Files Folder and then empty your "Recycle Bin" and reboot.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby Kagomelee » Fri Jun 18, 2004 5:45 pm

Thanks very much for your help. I feel so glad that I had the fortune to find a forum like this. The disgusting websides added by the spyware were deleted after I following your instructions.
But NTUSER files still can not be deleted. (The processes I found in the task manager are all normal, and I tried to delete some of them but that was of no use.)
Kagomelee
Newbie
Newbie
 
Posts: 3
Joined: Fri Jun 18, 2004 1:00 am

Thanks given:0
Thanks received:0
Top

Postby brad » Fri Jun 18, 2004 11:24 pm

So how's it running, other than the NTUSER files?
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby Kagomelee » Sat Jun 19, 2004 3:17 am

Kagomelee
Newbie
Newbie
 
Posts: 3
Joined: Fri Jun 18, 2004 1:00 am

Thanks given:0
Thanks received:0
Top


Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron