Hi!
My Daughters computer is dying from malware. I can't even run applications to detect, as they crash the system. I was able to run HiJack This in and here is what I got. Please help!
Thanks in Advance
Logfile of HijackThis v1.99.1
Scan saved at 11:32:25 AM, on 7/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\77f5a4f4.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\11253\explorer.exe
C:\WINDOWS\system32\spoolsvv.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
E:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\COMMON~1\ICROSO~1\RNDLL3~1.EXE
C:\Windows\xpupdate.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\RACLE~1\nopdb.exe
D:\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe"
O2 - BHO: (no name) - {1d662d41-02e4-423f-b182-14d0afbb453e} - C:\WINDOWS\system32\mrgeng.dll
O2 - BHO: (no name) - {38DD246F-B4DA-C207-A141-E82B56BB8490} - C:\WINDOWS\system32\qrfneaun.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: (no name) - {F77B350A-ABB2-D768-CD49-F8BAAF144AC0} - C:\WINDOWS\system32\larmk.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [amCoA] C:\docume~1\admini~1\locals~1\temp\amCoA.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vl6] C:\documents and settings\administrator\local settings\temp\Vl6.exe
O4 - HKLM\..\Run: [KQtu4] C:\documents and settings\administrator\local settings\temp\KQtu4.exe
O4 - HKLM\..\Run: [pqVvF] C:\documents and settings\administrator\local settings\temp\pqVvF.exe
O4 - HKLM\..\Run: [d3m] C:\documents and settings\administrator\local settings\temp\d3m.exe
O4 - HKLM\..\Run: [lZsz3Hll] C:\documents and settings\administrator\local settings\temp\lZsz3Hll.exe
O4 - HKLM\..\Run: [uaDdud2Zb] C:\documents and settings\administrator\local settings\temp\uaDdud2Zb.exe
O4 - HKLM\..\Run: [d3m.exe] C:\documents and settings\administrator\local settings\temp\d3m.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ÿ_zsk][BLPA] C:\WINDOWS\system32\_zskwrkni05KWQDXET^Z\APLB[].exe
O4 - HKLM\..\Run: [77f5a4f4.exe] C:\WINDOWS\system32\77f5a4f4.exe
O4 - HKLM\..\Run: [Explorer 2238] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\11253\explorer.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\System32\owinmrez.exe TST001
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Creative Detector] E:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Ifc] C:\DOCUME~1\ADMINI~1\MYDOCU~1\SEMBLY~1\POOLSV~1.EXE
O4 - HKCU\..\Run: [Nrou] "C:\PROGRA~1\RACLE~1\nopdb.exe" -vt yazr
O4 - HKCU\..\Run: [Rpe] C:\PROGRA~1\COMMON~1\ICROSO~1\RNDLL3~1.EXE
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [ÿ_zsk][BLPA] C:\WINDOWS\system32\_zskwrkni05KWQDXET^Z\APLB[].exe
O4 - HKCU\..\Run: [77f5a4f4.exe] C:\Documents and Settings\Administrator\Local Settings\Application Data\77f5a4f4.exe
O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\101.tmp3072.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\System32\owinmrez.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft\Office\OSA9.EXE
O4 - Global Startup: PowerReg Scheduler.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Encyclopedia - http://www.ezreference.com/_/ie-com-e-p3.htm
O8 - Extra context menu item: Web Rebates. - file://C:\Program Files\WebRebates4\websrebates\webtrebates\toprC0.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\aim.exe
O13 - WWW. Prefix: http://
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/NDWCab.CAB
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O20 - AppInit_DLLs: iniwin32.dll c:\windows\system32\dexplore.dll wuauboot.dll C:\WINDOWS\system32\rundll32.dll C:\WINDOWS\system32\wuauboot.dll
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll
O20 - Winlogon Notify: mrgeng - C:\WINDOWS\SYSTEM32\mrgeng.dll
O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\11253\explorer.exe
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_28.dll
O21 - SSODL: cpdBJuT - {9848497C-32E2-E3D6-E687-3FB895BA2790} - C:\WINDOWS\system32\he.dll (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
My Daughters computer is dying from malware. I can't even run applications to detect, as they crash the system. I was able to run HiJack This in and here is what I got. Please help!
Thanks in Advance
Logfile of HijackThis v1.99.1
Scan saved at 11:32:25 AM, on 7/29/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\77f5a4f4.exe
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\11253\explorer.exe
C:\WINDOWS\system32\spoolsvv.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
E:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\COMMON~1\ICROSO~1\RNDLL3~1.EXE
C:\Windows\xpupdate.exe
D:\Program Files\WinZip\WZQKPICK.EXE
C:\PROGRA~1\RACLE~1\nopdb.exe
D:\Program Files\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=explorer.exe "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe"
O2 - BHO: (no name) - {1d662d41-02e4-423f-b182-14d0afbb453e} - C:\WINDOWS\system32\mrgeng.dll
O2 - BHO: (no name) - {38DD246F-B4DA-C207-A141-E82B56BB8490} - C:\WINDOWS\system32\qrfneaun.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {C5183ABC-EB6E-4E05-B8C9-500A16B6CF94} - (no file)
O2 - BHO: (no name) - {F77B350A-ABB2-D768-CD49-F8BAAF144AC0} - C:\WINDOWS\system32\larmk.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [amCoA] C:\docume~1\admini~1\locals~1\temp\amCoA.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vl6] C:\documents and settings\administrator\local settings\temp\Vl6.exe
O4 - HKLM\..\Run: [KQtu4] C:\documents and settings\administrator\local settings\temp\KQtu4.exe
O4 - HKLM\..\Run: [pqVvF] C:\documents and settings\administrator\local settings\temp\pqVvF.exe
O4 - HKLM\..\Run: [d3m] C:\documents and settings\administrator\local settings\temp\d3m.exe
O4 - HKLM\..\Run: [lZsz3Hll] C:\documents and settings\administrator\local settings\temp\lZsz3Hll.exe
O4 - HKLM\..\Run: [uaDdud2Zb] C:\documents and settings\administrator\local settings\temp\uaDdud2Zb.exe
O4 - HKLM\..\Run: [d3m.exe] C:\documents and settings\administrator\local settings\temp\d3m.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\Program Files\Internet Explorer\IEXPLORE.EXE
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [ÿ_zsk][BLPA] C:\WINDOWS\system32\_zskwrkni05KWQDXET^Z\APLB[].exe
O4 - HKLM\..\Run: [77f5a4f4.exe] C:\WINDOWS\system32\77f5a4f4.exe
O4 - HKLM\..\Run: [Explorer 2238] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\11253\explorer.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\System32\owinmrez.exe TST001
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Creative Detector] E:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [Ifc] C:\DOCUME~1\ADMINI~1\MYDOCU~1\SEMBLY~1\POOLSV~1.EXE
O4 - HKCU\..\Run: [Nrou] "C:\PROGRA~1\RACLE~1\nopdb.exe" -vt yazr
O4 - HKCU\..\Run: [Rpe] C:\PROGRA~1\COMMON~1\ICROSO~1\RNDLL3~1.EXE
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [ÿ_zsk][BLPA] C:\WINDOWS\system32\_zskwrkni05KWQDXET^Z\APLB[].exe
O4 - HKCU\..\Run: [77f5a4f4.exe] C:\Documents and Settings\Administrator\Local Settings\Application Data\77f5a4f4.exe
O4 - HKCU\..\Run: [WinMedia] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\101.tmp3072.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\System32\owinmrez.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft\Office\OSA9.EXE
O4 - Global Startup: PowerReg Scheduler.exe
O4 - Global Startup: WinZip Quick Pick.lnk = D:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Encyclopedia - http://www.ezreference.com/_/ie-com-e-p3.htm
O8 - Extra context menu item: Web Rebates. - file://C:\Program Files\WebRebates4\websrebates\webtrebates\toprC0.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\aim.exe
O13 - WWW. Prefix: http://
O15 - Trusted Zone: http://www.neededware.com
O16 - DPF: NDWCab - http://www.neededware.com/NDWCab.CAB
O16 - DPF: Yahoo! Bingo - http://download.games.yahoo.com/games/clients/y/xt0_x.cab
O16 - DPF: Yahoo! Go Fish - http://download.games.yahoo.com/games/clients/y/zt3_x.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52...pple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O20 - AppInit_DLLs: iniwin32.dll c:\windows\system32\dexplore.dll wuauboot.dll C:\WINDOWS\system32\rundll32.dll C:\WINDOWS\system32\wuauboot.dll
O20 - Winlogon Notify: artm_newreg - C:\Documents and Settings\All Users\Documents\Settings\artm_new.dll
O20 - Winlogon Notify: mrgeng - C:\WINDOWS\SYSTEM32\mrgeng.dll
O21 - SSODL: DCOM Server 2238 - {2C1CD3D7-86AC-4068-93BC-A02304BB2238} - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\11253\explorer.exe
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\system32\2236_28.dll
O21 - SSODL: cpdBJuT - {9848497C-32E2-E3D6-E687-3FB895BA2790} - C:\WINDOWS\system32\he.dll (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe