PDA

View Full Version : Command Service (or some kind of downloader), HJT log file



DarkestSamus
2006-11-18, 11:18
Hello everybody!

I've been having some pop-up problems, as well as some random computer problems and sometimes slowness. Also, every time I run SpyBot (or AdAware or SBC Yahoo! Online Protection), I get several problems that seem to reoccur every time I clean them. Hence I assume I have a downloader.

SBC Yahoo! Online Protection gives me two programs, "CmdService" and "CasMedia", which it won't delete. SpyBot finds a "Command Service" but cannot remove it. I'm guessing that's my downloader, because it seems to clean everything else.

Well, here's my info... please help guys. :) Thank you!

Hijackthis Log File:

Logfile of HijackThis v1.99.1
Scan saved at 1:03:34 AM, on 11/18/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\Brmfrmps.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\ZCfgSvc.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\PROGRA~1\YAHOO!\browser\ybrwicon.exe
C:\Program Files\Dell TrueMobile 5100\GPRSMgr.exe
C:\Program Files\Java\j2re1.4.2_11\bin\jusched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\octeltpop.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\YAHOO!\YOP\yop.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\1XConfig.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R3 - URLSearchHook: (no name) - {88BE56EC-902A-E3AA-7801-BE896C0236EA} - C:\WINDOWS\System32\xgdhfh.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\YAHOO!\common\yiesrvc.dll
O2 - BHO: (no name) - {88BE56EC-902A-E3AA-7801-BE896C0236EA} - C:\WINDOWS\System32\xgdhfh.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\System32\ZCfgSvc.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\YAHOO!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [GC75-Manager-Class] "C:\Program Files\Dell TrueMobile 5100\GPRSMgr.exe" -startup
O4 - HKLM\..\Run: [AsioReg] REGSVR32 /S CTASIO.DLL
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_11\bin\jusched.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [1pop06apelt3] C:\WINDOWS\octeltpop.exe
O4 - HKLM\..\Run: [ikzad606] RUNDLL32.EXE w5610014.dll,n 006ad600000000025610014
O4 - HKLM\..\Run: [{5D-D3-3C-CD-ZN}] C:\windows\system32\nqdsregp.exe ELT001
O4 - HKLM\..\Run: [IpWins] C:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\YAHOO!\YOP\yop.exe /autostart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [Aham] "C:\DOCUME~1\User\MYDOCU~1\FNTS~1\tracert.exe" -vt yazr
O4 - HKCU\..\Run: [Oxbzb] C:\WINDOWS\SYSTEM32\s?stem32\w?wexec.exe
O4 - HKCU\..\Run: [mozi] C:\PROGRA~1\COMMON~1\mozi\mozim.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\YAHOO!\common\yiesrvc.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n020p/EN/install/gtdownlr.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/controls/ysftcntr/ysftcntr_current.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\SYSTEM32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\VXNlcg\command.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

DarkestSamus
2006-11-18, 11:18
Panda Online Scan (Search: My Computer):


Incident Status Location

Spyware:Spyware/Media-motor Not disinfected c:\windows\octeltpop.exe
Spyware:spyware/media-motor Not disinfected c:\windows\unstall.exe
Adware:adware/commad Not disinfected Windows Registry
Adware:adware/sqwire Not disinfected Windows Registry
Possible Virus. Renamed C:\WINDOWS\SYSTEM32\s?stem32\w?wexec.exe
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\s?stem32\1C4.tmp
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\s?stem32\67B.tmp
Adware:Adware/CommAd Not disinfected C:\WINDOWS\VXNlcg\prh5w0.vbs
Virus:Trj/KillAV.EX Disinfected C:\WINDOWS\TEMP\ja.exe
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{33C5D3CD-063A-1033-0630-051120030001}\Uninst.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
Virus:Trj/Agent.CRR Disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9B.tmp
Adware:Adware/SearchAid Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA6.tmp
Adware:Adware/Zenosearch Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAA.tmp
Spyware:Spyware/New.net Not disinfected C:\Program Files\filesubmit\ascension28.zip\NNWDAC638.EXE
Adware:Adware/SaveNow Not disinfected C:\Program Files\filesubmit\ascension28.zip\Ezthemes_WhenUSaveNow_InstallerInst.exe
Adware:Adware/ISearch Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b104.exe[MTE3MTk6ODoxNg.exe]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b104.exe[²ÜÇ\nsRandom.dll]
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b103.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b116.exe
Adware:Adware/EliteBar Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b111.exe
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b122.exe
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\User\Local Settings\Temp\temp.fr0732\Programs\webhdll.to_be_deleted
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\User\Local Settings\Temp\mit73.tmp
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\User\Local Settings\Temp\mit73.tmp.cab
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\User\Cookies\user@did-it[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\User\Cookies\user@www.myaffiliateprogram[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Cookies\user@ad.yieldmanager[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Cookies\user@ad.yieldmanager[3].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.enhance[1].txt
Possible Virus. Not disinfected C:\RemoveWGA.rar[RemoveWGA.exe]

DarkestSamus
2006-11-18, 11:19
Panda Online Scan (Search: Local Disks)


Incident Status Location

Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\xgdhfh.dll
Possible Virus. Renamed C:\WINDOWS\SYSTEM32\s?stem32\w?wexec.exe
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\s?stem32\1C4.tmp
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\s?stem32\3F1.tmp
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\s?stem32\67B.tmp
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM32\s?stem32\85C.tmp
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\octeltpop.exe
Spyware:spyware/media-motor Not disinfected C:\WINDOWS\unstall.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\VXNlcg\prh5w0.vbs
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{33C5D3CD-063A-1033-0630-051120030001}\Uninst.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
Adware:Adware/SearchAid Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA6.tmp
Adware:Adware/Zenosearch Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAA.tmp
Spyware:Spyware/New.net Not disinfected C:\Program Files\filesubmit\ascension28.zip\NNWDAC638.EXE
Adware:Adware/SaveNow Not disinfected C:\Program Files\filesubmit\ascension28.zip\Ezthemes_WhenUSaveNow_InstallerInst.exe
Adware:Adware/ISearch Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b104.exe[MTE3MTk6ODoxNg.exe]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b104.exe[²ÜÇ\nsRandom.dll]
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b103.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b116.exe
Adware:Adware/EliteBar Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b111.exe
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b122.exe
Adware:Adware/WebHancer Not disinfected C:\Documents and Settings\User\Local Settings\Temp\temp.fr0732\Programs\webhdll.to_be_deleted
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\User\Local Settings\Temp\mit73.tmp
Adware:Adware/Mirar Not disinfected C:\Documents and Settings\User\Local Settings\Temp\mit73.tmp.cab
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\User\Cookies\user@did-it[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\User\Cookies\user@www.myaffiliateprogram[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Cookies\user@ad.yieldmanager[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Cookies\user@ad.yieldmanager[3].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.enhance[1].txt
Possible Virus. Not disinfected C:\RemoveWGA.rar[RemoveWGA.exe]

Mr_JAk3
2006-11-20, 19:54
Hi DarkestSamus and welcome to Safer Networking Forums :)

You got infections there...

Before we can start the cleaning I need you to do something important.

Please download and install Windows XP Service Pack 1A -> Windows XP SP1a (http://www.microsoft.com/windowsxp/downloads/updates/sp1/default.mspx)
NOTE! Do NOT install Service Pack 2 yet. We'll have to get you cleaned first

Post a fresh HijackThis log to here when you're ready :bigthumb:

tashi
2006-11-27, 20:36
This topic is closed due to lack of a response to helper, if you need it re-opened please send me a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.