It is currently Tue Sep 01, 2026 4:25 pm


Help with Hijack Log

Is your PC infected? Is it running slow? Just can't figure out what's making it sluggish? Here is the place to get some help.

Moderators: liljim, Gecko

Tuesday Morning

Postby jerry » Tue Jun 22, 2004 1:34 pm

I have tried over a dozen time to get TrojanRemover loaded and operating and I have had no success. It always comes up that the files have been corrupted by a bad sector of the harddrive or a virus.......

I don't understand this - I wonder if it is related to not being able to find the shell.dll file??????????/

The above HJT file is still valid - I have not tried to fix anything since posting it,,,,,,,

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Tue Jun 22, 2004 4:13 pm

Let's try this again. Boot into "Safe Mode".
Turn off "System Restore". Don't turn it back on until you know this is repaired.

Press Ctrl/Alt/Del and "End Task" or "End Process" on each of the following: (They may or may not be there)

Close all other open Windows and have HiJackThis Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {24D00819-A6B4-4042-BE19-FAACB92CBF0E} - C:\WINDOWS\System32\bibfjb.dll

Now delete these Folders or Files that are Highlighted: (You may need enable "Show all Files" and disable "Hide System Files" in Windows Explorer / Tools / Folder Options / View Tab)

C:\WINDOWS\System32\bibfjb.dll

Now, empty:
C:\Documents and Settings\Jerry....\Local Settings\Temp
C:\Documents and Settings\Administrator\Local Settings\Temp
C:\Temp
C:\WINDOWS\Temp
and then empty your "Recycle Bin" and reboot.[/b]

Run HJT and Post the Log File.
Don't fix anything.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Tuesday 11:28 am

Postby jerry » Tue Jun 22, 2004 5:32 pm

Hello Brad,,,,,,,,,,okay I completed all the tasks just as you noted - here is the HJT log and it sure looks good to me - I had not been deleting the Admin Temp folder and that sp document was in it when I opened it to delete the folder - just maybe this will get the bug out - keeping fingers crossed..........

Logfile of HijackThis v1.97.7
Scan saved at 11:25:33 AM, on 6/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kansascity.com/mld/kansascity/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Tue Jun 22, 2004 6:07 pm

Fingers are crossed. Good job, Jerry.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Postby brad » Tue Jun 22, 2004 6:08 pm

Fingers are crossed. Good job, Jerry.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Still a problem Brad

Postby jerry » Tue Jun 22, 2004 11:37 pm

I was gone for about 3 hours and just clicked to open IE and it got me again. I haven't fixed znything just ran the HJT log for you - looks just the same as before except like you said the dll file is different. Whatever exe was installed (hidden) seems to work with a time setting - it stays clean for a couple of hours and then executes the Trojan again.

The description of the registry is prefixed with CWS which I assume is CooWebSearch variant. You know whoever is developing this could sure be an asset to the computer world if they only worked for the good of the people like you do!!!!!!!!!

HJT log:

Logfile of HijackThis v1.97.7
Scan saved at 5:27:41 PM, on 6/22/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Microsoft Office\Office\1033\MSOFFICE.EXE
C:\WINDOWS\system32\ntvdm.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = file://C:\DOCUME~1\JERRYT~1\LOCALS~1\Temp\sp.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {375C3B05-37D6-4553-BB33-A444769BA78C} - C:\WINDOWS\System32\njh.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8


jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Update

Postby jerry » Wed Jun 23, 2004 1:31 am

Brad, I have left the PC just as the previous post shows the HJT log. I did go out and download and run a program called Trojan Hunter. I thought maybe it would give us alittle more insight as to where this thing had been added. I copied the result of that scan and will post it here for you to take a look at. The program will not delete anything unless you pay $39.00 for the registration. What is wierd is that all of the files that I questioned as being strange executable files are also listed in this scan.

I don't have the nerve to just go delete them without your approval.

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan

Warning: Unable to unpack UPX-packed file C:\WINDOWS\addjt32.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\addou.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\addyz32.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\appxo.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\d3aj32.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\ienx.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\iprg.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\mfcqz.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\netws.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\netxr.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\ntcs32.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\syseq.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\sysid.exe
Warning: Unable to unpack UPX-packed file C:\WINDOWS\system32\addfk.exe
Found possible trojan file: C:\WINDOWS\system32\addfk.exe (Suspicious: UPX-packed file in Windows System folder)

Warning: Unable to unpack UPX-packed file C:\WINDOWS\system32\atllh32.exe
Found possible trojan file: C:\WINDOWS\system32\atllh32.exe (Suspicious: UPX-packed file in Windows System folder)

Warning: Unable to unpack UPX-packed file C:\WINDOWS\system32\d3kc.exe

Found possible trojan file: C:\WINDOWS\system32\d3kc.exe (Suspicious: UPX-packed file in Windows System folder)

Warning: Unable to unpack UPX-packed file C:\WINDOWS\system32\ipzz32.exe
Found possible trojan file: C:\WINDOWS\system32\ipzz32.exe (Suspicious: UPX-packed file in Windows System folder)

Warning: Unable to unpack UPX-packed file C:\WINDOWS\system32\netgd32.exe
Found possible trojan file: C:\WINDOWS\system32\netgd32.exe (Suspicious: UPX-packed file in Windows System folder)

Warning: Unable to unpack UPX-packed file C:\WINDOWS\system32\winpk32.exe
Found possible trojan file: C:\WINDOWS\system32\winpk32.exe (Suspicious: UPX-packed file in Windows System folder)

Warning: Unable to unpack UPX-packed file C:\WINDOWS\winah.exe
Warning: Unable to unpack UPX-packed file C:\Zipped Files\AdbeRdr60_enu_full.exe

6 possible trojan files found

After I ran this search I removed Trojan Hunter from my PC.

What are your thoughts?????????

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby teststrips » Wed Jun 23, 2004 1:53 am

it probably wouldn't hurt to rename the files that Trojan Hunter found while booted in safemode.

If your comptuter boots fine and runs normally then delete them. I'd put something like BADFILE before the existing filename.... then you can use the find function later and just search for badfile.. that way you don't have to browse around to find them all again.
User avatar
teststrips
Geek Alumni
 
Posts: 542
Joined: Fri Jan 24, 2003 1:00 am
Location: USA - Pennsylvania

Thanks given:0
Thanks received:0
Top

Postby brad » Wed Jun 23, 2004 7:04 am

I want to agree with teststrips but if we do that then any program we use to kill this Trojan/Worm may not detect it all. At the rate we're going though, we may have too.
Although I searched every .exe in the list and mainly got no results or just 1 hit, which was this Topic. :(
Almost everyone of them is a randomly generated .exe.
I found this on the sysid.exe. It's a Worm. We got rid of it earlier but I think that was before you started emptying all your Temp Folders.
This is a download from your AV - Norton. For removal of sysid.exe download this and follow Nortons instructions on updating your NAV.

Also, I found this Forum Topic that goes along with what teststrips said:

Try the Norton Update. Post back with the results.
Also, try turning off Norton completely and installing the Trojan Remover I had you download.

Post back... we'll get this thing.

brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Norton Antivirus

Postby jerry » Wed Jun 23, 2004 11:15 am

Good Morning,,,,,,,,,,,I went out and updated Norton but it said I had all of the most recent updates. So I booted into Safe Mode and ran HJT and repaired all of the bad stuff - I then went to the sysid.exe and renamed it badfilesysid.exe - emptied all of the Temp files both Jerry and Admin - then rebooted - everything booted just fine - I disabled the Norton and tried the TrojanRemover again but it gave me the same error message and would not run.

I ran HJT and here is the file:

Logfile of HijackThis v1.97.7
Scan saved at 5:06:13 AM, on 6/23/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Utilities\NProtect.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Jerry Thornton\Desktop\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kansascity.com/mld/kansascity/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.kansascity.com/mld/kansascitystar/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.kansascity.com/mld/kansascitystar/
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [QOELOADER] C:\Program Files\Qurb\QSP-2.1.213.0\QOELoader.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: www.pogo.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsup ... rtutil.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://active.macromedia.com/director/cabs/sw.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupda ... t/opuc.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/C ... .718912037
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsup ... mAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shoc ... wflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsup ... veData.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C4D9B8-FE9B-42FF-B730-0958349C8CF5}: NameServer = 151.164.8.201,151.164.1.8

Again it looks good right now - maybe we try this one at a time and see if it fixes it -- open for your suggestions.

I didn't have time to read the article that you posted Brad but I will this afternoon when I get home from work.

Thanks for staying with me on this - WE WILL WIN :)

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Wed Jun 23, 2004 11:22 am

Did you dowmload the specific link I gave you for Norton? The sysid download does not come with the Live Updates.
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Tuesday Afternoon

Postby jerry » Wed Jun 23, 2004 6:20 pm

Hi Brad,,,,,,,,,,yes I went to the Norton site and did the manual download -it still said that my Norton was up to date with all new downloads - I ran live update several times after that and it tells me that it is up to date.

I left the PC on all the time I was gone to work - 5:30 am until I just got home and it is still just fine, hmmmmmmmm makes ya wonder??????

The only thing I really did that was not on your list to do was get the TrojanRemover to work and I changed the name of the sysid.exe file to badfilesysid.exe ------------ now I wonder about all the rest of those suspicious exe files --------- do you think I should rename them as bad and then delete them if everything works well???????? Or Should I leave well enough alone??? Should I go delete the file I renamed?

I think you found the problem - it being that sysid.exe file.

I ran SpyBot and it found no problems. I ran HJT and it looks clean too.

Please give me your thoughts on these questions - I truly believe that you fixed the major problem ------- THANK YOU SO VERY MUCH!!!!

jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

update Wednesday evening

Postby jerry » Thu Jun 24, 2004 3:37 am

Welllllllllll it hit me again this evening so I went out and read the link that you posted and went in and deleted everything that looked suspicious - dat exe & dll files. I completed all the tasks that the gentleman said worked for him - hopefully I didn't miss any bad files.

Earlier today Norton updated and located 3 Trojans - it repaired one and I had to delete the other 2 manually - getmem.dat and winah.exe.

The darn thing looks good right at this time - HJT log and all so we will wait and see if it rears its ugly head again - will keep you posted.

Thanks again jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

Postby brad » Thu Jun 24, 2004 9:23 am

Ok....
brad
brad
Geek Alumni
 
Posts: 2079
Joined: Sat Jul 19, 2003 1:00 am
Location: Charlotte, NC

Thanks given:0
Thanks received:0
Top

Update Friday June 25th

Postby jerry » Fri Jun 25, 2004 10:13 pm

Hi Brad, I am giving you this update because I just can't get this thing fixed. I went in and deleted all of the files I could even guess might be the problem and the only thing I was successful at was deleting something that prevents me from connecting to my DSL service automatically.

With Windows XP all I had to do was click on IE and I was automatically connected through my router to the internet. Now I have to connect via a SBC Yahoo Dsl connection that we set up manually and I can't go through my router.

Every couple of hours I get the dang bug and my homepage changes and the HJT log looks just like it did before except the random dll file changes.

Would totally cleaning the harddrive (which I have never done before in my life) and re-installing Windows XP be the answer at this point?????

After going to Safe Mode and running HJT and deleting all the bad stuff the log looks great until the next time the bug launches - I would post the log but you have seen what it does so many times I know you are tired of looking at it.

Any suggestions are welcome --------

Jerry
User avatar
jerry
Geek
Geek
 
Posts: 57
Joined: Mon Nov 25, 2002 1:00 am
Location: Kansas City, MO

Thanks given:0
Thanks received:0
Top

PreviousNext

Return to Malware Support

Who is online

Users browsing this forum: No registered users and 0 guests

cron