PDA

View Full Version : Adware - xlibgfl254.dll



treevis_k
2007-03-03, 13:25
Seeing a possible trojan/adware (xlibgfl254.dll). Saw the other two threads with the same name. Could you please advise?

==========
a) The HJT log
==========
Logfile of HijackThis v1.99.1
Scan saved at 2:02:46 AM, on 3/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\PROGRAM FILES\DELL\MEDIA EXPERIENCE\PCMSERVICE.EXE
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRAM FILES\DELL SUPPORT\DSAGNT.EXE
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Program Files\Spirent Communications\Honolulu VPN Client\cvpnd.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PCCTLCOM.EXE
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TMPROXY.EXE
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Travis\My Documents\Spybot Forum Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.honoluluadvertiser.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2006\pccguide.exe"
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Spirent Communications Honolulu VPN Client.lnk = C:\Program Files\Spirent Communications\Honolulu VPN Client\vpngui.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.costcophotocenter.com/CostcoActivia.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Spirent Communications\Honolulu VPN Client\cvpnd.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe



===========================
b) The on-line Anti Virus scan log/report
Panda Online scan - activescan.txt:
===========================
Incident Status Location

Adware:Adware/SecurityError Not disinfected C:\WINDOWS\system32\xlibgfl254.dll
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tina\Cookies\tina@atwola[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tina\Cookies\tina@go[1].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tina\Cookies\tina@target[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@atwola[1].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@bfast[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@burstnet[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@cgi-bin[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@cgi-bin[4].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@drivecleaner[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@go[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@target[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@www.burstbeacon[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@yadro[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Travis\Cookies\travis@com[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Travis\Cookies\travis@go[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Travis\Cookies\travis@microsoftwga.112.2o7[1].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Travis\Cookies\travis@target[2].txt
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\Travis\Cookies\travis@tucows[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Travis\Cookies\travis@www.burstbeacon[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Travis\Cookies\travis@zedo[1].txt

shelf life
2007-03-04, 14:27
hi treevis_k,

enable all files:

launch hjt click on "open misc tools section" click on "delete a file on reboot"
copy/paste this in the window and click open
C:\WINDOWS\system32\xlibgfl254.dll

when asked to reboot, select yes.
-----------------------------------------------
after rebooting, please do another panda online scan to see if it is gone.

shelf life

treevis_k
2007-03-05, 01:00
thanks for the quick reply, shelf life! I'll run the panda scan and post the report.

treevis_k
2007-03-05, 02:01
Forgot to mention that I did the HJT steps. Ran the Panda online scan (doesn't list "xlibgfl254.dll"). But during the panda online scan I got a PC-cillin warning on the "xlibgfl254.dll" file - it was quarantined and removed.

==========

Incident Status Location

Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tina\Cookies\tina@atwola[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tina\Cookies\tina@go[1].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tina\Cookies\tina@target[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@atwola[1].txt
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@bfast[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@burstnet[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@cgi-bin[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@cgi-bin[4].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@drivecleaner[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@go[2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@target[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@www.burstbeacon[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Tina.DELL_I6000\Cookies\tina@yadro[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Travis\Cookies\travis@ad.yieldmanager[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Travis\Cookies\travis@com[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Travis\Cookies\travis@statcounter[1].txt

shelf life
2007-03-05, 22:52
hi treevis_k,


it was quarantined and removed
ok good. rest of hjt log looks ok. everything ok now on that end now?

heres a good free app for deleting cookies, temp files etc. i would use it every so often:

http://www.atribune.org/content/view/19/2/

shelf life

treevis_k
2007-03-08, 09:17
Thanks Shelf Life! So is there anything else I need to do? I haven't seen the xlibgfl254.dll file reappear since it was quarantined. I visited that post by TonyKlein (for several layers of protection) while browsing before posting and installed some of those apps.

shelf life
2007-03-08, 22:56
hi treevis_k,

good. glad to help.happy safe surfing. for your reference:

Prevention-or How Can I Help Myself? (http://security-central.us/SafeHex/prevention.htm)