Josh24601
2006-09-13, 12:59
Hi,
I think my browser may have been hijacked as I was sometimes directed to a different website from my intended one.
Then I downloaded and installed Spybot, ran it, and removed a number of detected items such as:
KillAndClean, Pipas.A and a few others that I can't remember.
I then realised after running Spybot again that Pipas.A was still being detected, looked up this forum for help, and read the following link, http://forums.spybot.info/showthread.php?t=288
Then I went to Bitdefender to do an online virus scan and left it overnight, but when I woke up found that my computer had crashed, so I have no way of finding out if the scan completed, and what files were being deleted.
Anyway, I scanned it again with Bitdefender, and followed the rest of the instructions from the above link.
(sorry for the longwinded post)
Below are the contents of the report from the online scan:
================================================
BitDefender Online Scanner
Scan report generated at: Wed, Sep 13, 2006 - 15:09:26
Scanned File
Status
C:\WINDOWS\SYSTEM\{04FEB7E4-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.Click.526
C:\WINDOWS\SYSTEM\{04FEB7E4-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E4-419B-11DB-9765-00E04C030C00}.exe
Deleted
C:\WINDOWS\SYSTEM\{04FEB7E5-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.Fakealert
C:\WINDOWS\SYSTEM\{04FEB7E5-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E5-419B-11DB-9765-00E04C030C00}.exe
Deleted
C:\WINDOWS\SYSTEM\{04FEB7E6-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.Clicker.AA
C:\WINDOWS\SYSTEM\{04FEB7E6-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E6-419B-11DB-9765-00E04C030C00}.exe
Deleted
C:\WINDOWS\SYSTEM\{04FEB7E7-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.FakeAlert.CR
C:\WINDOWS\SYSTEM\{04FEB7E7-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E7-419B-11DB-9765-00E04C030C00}.exe
Deleted
Below are the contents of the HJT logfile (text enclosed with **<comment>** are removed for privacy reasons):
================================
Logfile of HijackThis v1.99.1
Scan saved at 5:04:07 PM, on 9/13/06
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\THOTKEY.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\SYSTEM\TFUNCKEY.EXE
C:\WINDOWS\SYSTEM\TPWRMGR.EXE
C:\WINDOWS\SYSTEM\TOSHIBSU.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = **valid startpage - asterisked for privacy**
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = **valid proxy - asterisked for privacy**
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = **asterisked for privacy**<local>
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: IEHlprObj Class - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [TFunckey] TFunckey.Exe
O4 - HKLM\..\Run: [TPwrMgr] TPwrMgr.Exe
O4 - HKLM\..\Run: [TOSHIBSU] TOSHIBSU.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [THotkey] THotkey.Exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] c:\windows\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: Download with Go!Zilla - file://C:\PROGRAM FILES\GO!ZILLA\download-with-gozilla.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: SearchAssistant=
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/win/QuickTimeInstaller.exe
O16 - DPF: {65231111-1111-1111-1111-111177773458} - file://C:\WINDOWS\Tempor~1\Content.IE5\KTCPUJ85\epl80[1].cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.116.73,85.255.112.150
Sorry for having to asterisked out some fields; they reveal some information about my whereabouts that I'm not willing to risk divulging, but I can guarantee that they are not needed.
Thanks for any help.
Josh
I think my browser may have been hijacked as I was sometimes directed to a different website from my intended one.
Then I downloaded and installed Spybot, ran it, and removed a number of detected items such as:
KillAndClean, Pipas.A and a few others that I can't remember.
I then realised after running Spybot again that Pipas.A was still being detected, looked up this forum for help, and read the following link, http://forums.spybot.info/showthread.php?t=288
Then I went to Bitdefender to do an online virus scan and left it overnight, but when I woke up found that my computer had crashed, so I have no way of finding out if the scan completed, and what files were being deleted.
Anyway, I scanned it again with Bitdefender, and followed the rest of the instructions from the above link.
(sorry for the longwinded post)
Below are the contents of the report from the online scan:
================================================
BitDefender Online Scanner
Scan report generated at: Wed, Sep 13, 2006 - 15:09:26
Scanned File
Status
C:\WINDOWS\SYSTEM\{04FEB7E4-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.Click.526
C:\WINDOWS\SYSTEM\{04FEB7E4-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E4-419B-11DB-9765-00E04C030C00}.exe
Deleted
C:\WINDOWS\SYSTEM\{04FEB7E5-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.Fakealert
C:\WINDOWS\SYSTEM\{04FEB7E5-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E5-419B-11DB-9765-00E04C030C00}.exe
Deleted
C:\WINDOWS\SYSTEM\{04FEB7E6-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.Clicker.AA
C:\WINDOWS\SYSTEM\{04FEB7E6-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E6-419B-11DB-9765-00E04C030C00}.exe
Deleted
C:\WINDOWS\SYSTEM\{04FEB7E7-419B-11DB-9765-00E04C030C00}.exe
Infected with: Trojan.FakeAlert.CR
C:\WINDOWS\SYSTEM\{04FEB7E7-419B-11DB-9765-00E04C030C00}.exe
Disinfection failed
C:\WINDOWS\SYSTEM\{04FEB7E7-419B-11DB-9765-00E04C030C00}.exe
Deleted
Below are the contents of the HJT logfile (text enclosed with **<comment>** are removed for privacy reasons):
================================
Logfile of HijackThis v1.99.1
Scan saved at 5:04:07 PM, on 9/13/06
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\THOTKEY.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\IRMON.EXE
C:\WINDOWS\SYSTEM\TFUNCKEY.EXE
C:\WINDOWS\SYSTEM\TPWRMGR.EXE
C:\WINDOWS\SYSTEM\TOSHIBSU.EXE
C:\WINDOWS\LOADQM.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\QTTASK.EXE
C:\WINDOWS\RunDLL.exe
C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\TEATIMER.EXE
C:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE\OSA.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\HIJACKTHIS\HIJACKTHIS.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = **valid startpage - asterisked for privacy**
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://keyword.netscape.com/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = **valid proxy - asterisked for privacy**
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = **asterisked for privacy**<local>
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: IEHlprObj Class - {CD4C3CF0-4B15-11D1-ABED-709549C10000} - C:\PROGRAM FILES\GO!ZILLA\GOIEHLP.DLL (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [IrMon] IrMon.exe
O4 - HKLM\..\Run: [TFunckey] TFunckey.Exe
O4 - HKLM\..\Run: [TPwrMgr] TPwrMgr.Exe
O4 - HKLM\..\Run: [TOSHIBSU] TOSHIBSU.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [OEMCleanup] C:\WINDOWS\OPTIONS\OEMRESET.EXE
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\RunServices: [THotkey] THotkey.Exe
O4 - HKLM\..\RunServices: [Machine Debug Manager] C:\WINDOWS\SYSTEM\MDM.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] c:\windows\SYSTEM\mstask.exe
O4 - HKCU\..\Run: [Taskbar Display Controls] RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O8 - Extra context menu item: Download with Go!Zilla - file://C:\PROGRAM FILES\GO!ZILLA\download-with-gozilla.html
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O14 - IERESET.INF: SearchAssistant=
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20060104/qtinstall.info.apple.com/snape/us/win/QuickTimeInstaller.exe
O16 - DPF: {65231111-1111-1111-1111-111177773458} - file://C:\WINDOWS\Tempor~1\Content.IE5\KTCPUJ85\epl80[1].cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 85.255.116.73,85.255.112.150
Sorry for having to asterisked out some fields; they reveal some information about my whereabouts that I'm not willing to risk divulging, but I can guarantee that they are not needed.
Thanks for any help.
Josh