PDA

View Full Version : my PC got owned



taotsu
2006-10-12, 03:07
here's the log...

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\iolo\System Mechanic 6\IoloSGCtrl.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\iolo\System Mechanic 6\SystemGuardAlerter.exe
C:\PROGRA~1\PRINTV~1\pvmodule.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Ultimate Cleaner\App.exe
C:\Program Files\iolo\System Mechanic 6\PopupBlocker.exe
C:\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: (no name) - {4472E2B2-FB44-FBD4-2A58-0101EBECF47E} - C:\WINDOWS\system32\ksrpmje.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - C:\WINDOWS\system32\ixt0.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PrintViewBHO Class - {D4E0C464-30CE-4075-9A10-71FD106C2847} - C:\PROGRA~1\PRINTV~1\PRINTH~1.DLL
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [SystemGuardAlerter] "C:\Program Files\iolo\System Mechanic 6\SystemGuardAlerter.exe"
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic 6\delay.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [PVModule] C:\PROGRA~1\PRINTV~1\pvmodule.exe
O4 - HKLM\..\Run: [ikrfind.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ikrfind.dll,buptmcd
O4 - HKLM\..\Run: [Ultimate Cleaner] C:\Program Files\Ultimate Cleaner\App.exe
O4 - HKCU\..\Run: [System Mechanic Popup Blocker] "C:\Program Files\iolo\System Mechanic 6\PopupBlocker.exe"
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {01118A01-3E00-11D2-8470-0060089874ED} (SupportSoft Script Runner Class) - https://password.bellsouth.net/sdccommon/download/tgctlsr.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {89981B1D-07DA-43C3-9770-06C51E7E5DCE} (NostaleWebStarter Control) - http://game.nostale.com/sso/NostaleWebLauncher.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin9USA.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) - http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame.com/KALogoutComponent.cab
O16 - DPF: {E1AC9563-A1E3-45B8-A5CE-5C19E34EC6AC} (ComTop Class) - http://www.arirangtv.com/AlwaysTop.cab
O20 - Winlogon Notify: awvtr - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winccf32 - C:\WINDOWS\SYSTEM32\winccf32.dll
O20 - Winlogon Notify: winjgf32 - winjgf32.dll (file missing)
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iolo System Guard (IOLO_SRV) - Unknown owner - C:\Program Files\iolo\System Mechanic 6\IoloSGCtrl.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

taotsu
2006-10-12, 06:16
scanned my PC with Pandascan and it found 3 virus and a dialer among all the cookies, spywares, and adwares. i'm going to be selective on who can use my PC now. i'd appreciate any help i can get. this is the log from Pandascan...


Incident

Adware:Adware/PrintView
Adware:Adware/PrintView
Adware:Adware/SafetyBar
Adware:Adware/UltimateCleaner
Adware:Adware/SuperSpider
Adware:adware/systemdoctor
Adware:adware/securityerror
Adware:adware/emediacodec
Adware:adware/mirar
Dialer:dialer.avv
Adware:adware/commad
Adware:adware/yazzle
Spyware:Cookie/Zedo
Spyware:Cookie/Atlas DMT
Spyware:Cookie/Advertising
Spyware:Cookie/Doubleclick
Spyware:Cookie/Tribalfusion
Spyware:Cookie/RealMedia
Spyware:Cookie/2o7
Spyware:Cookie/YieldManager
Spyware:Cookie/Adrevolver
Spyware:Cookie/AdDynamix
Spyware:Cookie/PointRoll
Spyware:Cookie/Apmebf
Spyware:Cookie/Falkag
Spyware:Cookie/Atwola
Spyware:Cookie/Azjmp
Spyware:Cookie/Belnk
Spyware:Cookie/BurstNet
Spyware:Cookie/Ccbill
Spyware:Cookie/Clickbank
Spyware:Cookie/Com.com
Spyware:Cookie/cs.sexcounter
Spyware:Cookie/did-it
Spyware:Cookie/DriveCleaner
Spyware:Cookie/Maxserving
Spyware:Cookie/Overture
Spyware:Cookie/Overture
Spyware:Cookie/QkSrv
Spyware:Cookie/QuestionMarket
Spyware:Cookie/RealMedia
Spyware:Cookie/WUpd
Spyware:Cookie/Serving-sys
Spyware:Cookie/SpyLog
Spyware:Cookie/Statcounter
Spyware:Cookie/Reliablestats
Spyware:Cookie/Toplist
Spyware:Cookie/Tradedoubler
Spyware:Cookie/Traffic Marketplace
Spyware:Cookie/Weborama
Spyware:Cookie/DriveCleaner
Spyware:Cookie/Xiti
Spyware:Cookie/Adserver
Spyware:Cookie/YieldManager
Spyware:Cookie/Comclick
Spyware:Cookie/BurstBeacon
Spyware:Cookie/2o7
Spyware:Cookie/YieldManager
Spyware:Cookie/Adrevolver
Spyware:Cookie/Adrevolver
Spyware:Cookie/Banner
Spyware:Cookie/DriveCleaner
Spyware:Cookie/Overture
Spyware:Cookie/WUpd
Spyware:Cookie/Reliablestats
Spyware:Cookie/DriveCleaner
Spyware:Spyware/Virtumonde
Spyware:Spyware/Virtumonde
Adware:Adware/PrintView
Adware:Adware/PrintView
Virus:Bck/TclockBased.A
Virus:Bck/TclockBased.A
Adware:Adware/UltimateCleaner
Adware:Adware/PurityScan
Adware:Adware/CommAd
Adware:Adware/SystemDoctor
Adware:Adware/PurityScan
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SecurityError
Spyware:Spyware/Virtumonde
Spyware:Spyware/Virtumonde
Spyware:Spyware/Virtumonde
Spyware:Spyware/Virtumonde
Adware:Adware/SpywareQuake
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Spyware:Cookie/Casalemedia
Spyware:Cookie/YieldManager
Spyware:Cookie/QuestionMarket
Spyware:Cookie/Advertising
Spyware:Cookie/Doubleclick
Spyware:Cookie/Advertising
Spyware:Cookie/RealMedia
Spyware:Cookie/Atlas DMT
Spyware:Cookie/RealMedia
Spyware:Cookie/Mediaplex
Spyware:Cookie/AdDynamix
Spyware:Cookie/2o7
Spyware:Cookie/Adrevolver
Spyware:Cookie/PointRoll
Spyware:Cookie/Falkag
Spyware:Cookie/Atwola
Spyware:Cookie/Belnk
Spyware:Cookie/BurstNet
Spyware:Cookie/Maxserving
Spyware:Cookie/WUpd
Spyware:Cookie/Statcounter
Spyware:Cookie/Tradedoubler
Spyware:Cookie/Traffic Marketplace
Spyware:Cookie/Tribalfusion
Spyware:Cookie/Adserver
Spyware:Cookie/Zedo
Spyware:Cookie/onestat.com
Spyware:Cookie/BurstBeacon
Spyware:Cookie/2o7
Spyware:Cookie/Searchportal
Spyware:Cookie/YieldManager
Spyware:Cookie/Malwarewipe
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/SystemDoctor
Adware:Adware/Adservice
Potentially unwanted tool:Application/Zango
Virus:Trj/Downloader.BRW

pskelley
2006-10-17, 01:44
Welcome to the forum, if you still need help and have not resolved your issues elsewhere, let's start like this.

1) You have a load of junk on your computer and this stuff will attract more, so I suggest you keep it offline as much as possible to avoid additional infections.

2) You have cut off the first four lines off the HJT log, this information is important, tells me the version of HJT is up to date and that your Windows Security is up to date, see this:
UPDATED WINDOWS - Your first line of defence, links and tips
http://forums.spybot.info/showthread.php?t=425

3) Let's start like this, follow the directions in this link: http://forums.spybot.info/showthread.php?t=4015 When you finish the instructions, post the three logs in this same topic using the "Post Reply" button.

Spybot-S&D: Be sure to follow the directions to save the scan report but do not post it here unless requested by a helper.

Thanks...pskelley
Safer Networking Forums

If you would like to let your thoughts be known about the lowlifes who put that junk on your computer, you can do that here:
If you have been infected by one of the SpyAxe family
http://forums.tomcoyote.org/index.php?showtopic=58063
http://www.malwarecomplaints.info/

tashi
2006-10-22, 03:49
This topic has been closed to prevent others with similar issues posting in it.
If you need it re-opened please send me or your helper a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.