Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 22

Thread: Smitfraud-C. Toolbar888 and WinAntiSpyware

  1. #11
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hello

    We'll continue..

    Go to virustotal.com
    Copy the following to the box next to "Browse" button:
    C:\WINDOWS\system32\j2261831.dll
    Click on Send
    Wait for the scan to end.

    Scan these two too:

    C:\WINDOWS\system32\j9251738.dll
    C:\WINDOWS\system32\alt.exe

    Copy & Paste the scan results to here.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  2. #12
    Junior Member
    Join Date
    May 2007
    Posts
    12

    Default

    here you go!

    results for C:\WINDOWS\system32\j2261831.dll

    Antivirus Version Update Result
    AhnLab-V3 2007.5.31.2 06.01.2007 no virus found
    AntiVir 7.4.0.29 06.01.2007 no virus found
    Authentium 4.93.8 05.23.2007 no virus found
    Avast 4.7.997.0 06.01.2007 no virus found
    AVG 7.5.0.467 06.01.2007 no virus found
    BitDefender 7.2 06.01.2007 no virus found
    CAT-QuickHeal 9.00 06.01.2007 no virus found
    ClamAV devel-20070416 06.01.2007 no virus found
    DrWeb 4.33 06.01.2007 no virus found
    eSafe 7.0.15.0 05.31.2007 no virus found
    eTrust-Vet 30.7.3682 06.01.2007 no virus found
    Ewido 4.0 06.01.2007 no virus found
    FileAdvisor 1 06.01.2007 no virus found
    Fortinet 2.85.0.0 06.01.2007 no virus found
    F-Prot 4.3.2.48 06.01.2007 no virus found
    F-Secure 6.70.13030.0 06.01.2007 no virus found
    Ikarus T3.1.1.8 06.01.2007 no virus found
    Kaspersky 4.0.2.24 06.01.2007 no virus found
    McAfee 5044 06.01.2007 no virus found
    Microsoft 1.2503 06.01.2007 no virus found
    NOD32v2 2305 06.01.2007 no virus found
    Norman 5.80.02 06.01.2007 no virus found
    Panda 9.0.0.4 06.01.2007 no virus found
    Prevx1 V2 06.01.2007 Polynomial.Code.Exploit
    Sophos 4.18.0 06.01.2007 no virus found
    Sunbelt 2.2.907.0 05.30.2007 no virus found
    Symantec 10 06.01.2007 no virus found
    TheHacker 6.1.6.128 05.31.2007 no virus found
    VBA32 3.12.0 06.01.2007 no virus found
    VirusBuster 4.3.23:9 06.01.2007 no virus found
    Webwasher-Gateway 6.0.1 06.01.2007 no virus found


    results for C:\WINDOWS\system32\j9251738.dll

    Antivirus Version Update Result
    AhnLab-V3 2007.5.31.2 06.01.2007 no virus found
    AntiVir 7.4.0.29 06.01.2007 no virus found
    Authentium 4.93.8 05.23.2007 no virus found
    Avast 4.7.997.0 06.01.2007 no virus found
    AVG 7.5.0.467 06.01.2007 no virus found
    BitDefender 7.2 06.01.2007 no virus found
    CAT-QuickHeal 9.00 06.01.2007 no virus found
    ClamAV devel-20070416 06.01.2007 no virus found
    DrWeb 4.33 06.01.2007 no virus found
    eSafe 7.0.15.0 05.31.2007 no virus found
    eTrust-Vet 30.7.3682 06.01.2007 no virus found
    Ewido 4.0 06.01.2007 no virus found
    FileAdvisor 1 06.01.2007 no virus found
    Fortinet 2.85.0.0 06.01.2007 no virus found
    F-Prot 4.3.2.48 06.01.2007 no virus found
    F-Secure 6.70.13030.0 06.01.2007 no virus found
    Ikarus T3.1.1.8 06.01.2007 no virus found
    Kaspersky 4.0.2.24 06.01.2007 no virus found
    McAfee 5044 06.01.2007 no virus found
    Microsoft 1.2503 06.01.2007 no virus found
    NOD32v2 2305 06.01.2007 no virus found
    Norman 5.80.02 06.01.2007 no virus found
    Panda 9.0.0.4 06.01.2007 no virus found
    Prevx1 V2 06.01.2007 Polynomial.Code.Exploit
    Sophos 4.18.0 06.01.2007 no virus found
    Sunbelt 2.2.907.0 05.30.2007 no virus found
    Symantec 10 06.01.2007 no virus found
    TheHacker 6.1.6.128 05.31.2007 no virus found
    VBA32 3.12.0 06.01.2007 no virus found
    VirusBuster 4.3.23:9 06.01.2007 no virus found
    Webwasher-Gateway 6.0.1 06.01.2007 no virus found



    results for C:\WINDOWS\system32\alt.exe

    Antivirus Version Update Result
    AhnLab-V3 2007.5.31.2 06.01.2007 no virus found
    AntiVir 7.4.0.29 06.01.2007 WORM/Zhelatin.Gen
    Authentium 4.93.8 05.23.2007 no virus found
    Avast 4.7.997.0 06.01.2007 no virus found
    AVG 7.5.0.467 06.01.2007 no virus found
    BitDefender 7.2 06.01.2007 Trojan.Peed.HVJ.Gen
    CAT-QuickHeal 9.00 06.01.2007 (Suspicious) - DNAScan
    ClamAV devel-20070416 06.01.2007 no virus found
    DrWeb 4.33 06.01.2007 Trojan.Packed.135
    eSafe 7.0.15.0 05.31.2007 Suspicious Trojan/Worm
    eTrust-Vet 30.7.3682 06.01.2007 Win32/Sintun
    Ewido 4.0 06.01.2007 no virus found
    FileAdvisor 1 06.01.2007 no virus found
    Fortinet 2.85.0.0 06.01.2007 W32/Tibs.Y!tr
    F-Prot 4.3.2.48 06.01.2007 no virus found
    F-Secure 6.70.13030.0 06.01.2007 Packed.Win32.Tibs.y
    Ikarus T3.1.1.8 06.01.2007 no virus found
    Kaspersky 4.0.2.24 06.01.2007 Packed.Win32.Tibs.y
    McAfee 5044 06.01.2007 no virus found
    Microsoft 1.2503 06.01.2007 Worm:Win32/Nuwar.gen
    NOD32v2 2305 06.01.2007 no virus found
    Norman 5.80.02 06.01.2007 Tibs.gen108
    Panda 9.0.0.4 06.01.2007 Suspicious file
    Prevx1 V2 06.01.2007 no virus found
    Sophos 4.18.0 06.01.2007 no virus found
    Sunbelt 2.2.907.0 05.30.2007 no virus found
    Symantec 10 06.01.2007 no virus found
    TheHacker 6.1.6.128 05.31.2007 no virus found
    VBA32 3.12.0 06.01.2007 no virus found
    VirusBuster 4.3.23:9 06.01.2007 no virus found
    Webwasher-Gateway 6.0.1 06.01.2007 Worm.Zhelatin.Gen

  3. #13
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi and sorry for the delay.

    Sorry for the delay, I wasn't on the reach of my pc yesterday.

    Hmm I need to take a closer look before we can continue...

    Please download the Suspicious file Packer from Safer-Networking.Org and unzip it to your desktop.

    Run SFP.exe.

    Please copy the following lines into the Step 1: Paste Text window:
    C:\WINDOWS\system32\qgacfwhx.exe
    C:\WINDOWS\system32\j2261831.dll
    C:\WINDOWS\system32\oyupenju.exe
    C:\WINDOWS\system32\j9251738.dll
    C:\WINDOWS\system32\uulkeano.exe
    C:\WINDOWS\system32\alt.exe
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\ytgloxyp.exe
    C:\WINDOWS\system32\lfhs76ghf.dll
    then click "Continue".

    This will create a .cab file on your desktop named requested-files[Date/Time].cab

    Please go to this forum
    There's no need to register. Just start a new topic in the Uploads section, titled "Files for Mr_JAk3".
    Copy the link of this topic to the message.

    Use the Attachment box to upload the cab file from your desktop.

    NOTE: You will not see the files that have been uploaded (including the ones you upload yourself) as they only show to the authorised users who can download them

    Thank you
    Last edited by Mr_JAk3; 2007-06-03 at 13:55.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  4. #14
    Junior Member
    Join Date
    May 2007
    Posts
    12

    Default

    No problem Mr_JAk3! I understand you have a life outside of helping people fix their computers..I really appreciate the help!

    I followed your instructions and uploaded requested-files[2007-06-03_12_00].cab to the Spykiller site under Uploads.

    I look forward to hearing back from you!

  5. #15
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi again, we'll continue

    Thank you for the uploads.

    You should print these instructions or save these to a text file. Follow these instructions carefully.

    Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
    http://www.ewido.net/en/download/
    • Install AVG Anti-Spyware by double clicking the installer.
    • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
    • On the main screen under Your Computer's security.
      • Click on Change state next to Resident shield. It should now change to inactive.
      • Click on Change state next to Automatic updates. It should now change to inactive.
      • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
      • Wait until you see the Update succesfull message.
    • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
    If you are having problems with the updater, you can use this link to manually update ewido.
    AVG Anti-Spyware manual updates.
    Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

    Download ATF Cleaner by Atribune to your desktop.
    Do NOT run yet.

    Please download the Killbox.
    Unzip it to the desktop but do NOT run it yet.


    ==================


    Backup your registry:
    • Start
    • Run
    • Type the following to the box and hit Ok: regedit
    • A window opens, click on File
    • Choose Export form the menu
    • Change the save location to C:\
    • Give the filename, RegBackUp
    • Make sure that the filetype is set to Registryfiles (*.reg)
    • Click on Save and Close the window



    Open Notepad (NOT WORDPAD!) and copy the following lines from the quote box below into a new document, leaving a blank line at the end. (don't forget to copy and paste the word REGEDIT4) :

    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{BEDF30ED-41B2-4CDC-875A-ED063C81AF7B}"=-

    Make sure there are NO blank lines before REGEDIT4
    Make sure there IS one blank line at the end of the file.

    Save the document to your desktop as Fix.reg and filetype: All Files
    Go to your desktop and double click on the file to run Fix.reg and when it asks you if you want to merge the contents to the registry, click yes/ok.

    Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list. Fix the O6 if you haven't locked Internet Explorer settings on purpose.

    O4 - HKLM\..\Run: [ytgloxyp.exe] C:\Documents and Settings\All Users\Application Data\ytgloxyp.exe
    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

    Please run Killbox.

    Select "Delete on Reboot".

    Copy the file names below to the clipboard by highlighting them and pressing Control-C:
    C:\WINDOWS\system32\qgacfwhx.exe
    C:\WINDOWS\system32\j2261831.dll
    C:\WINDOWS\system32\oyupenju.exe
    C:\WINDOWS\system32\j9251738.dll
    C:\WINDOWS\system32\j7271830.dll
    C:\WINDOWS\system32\myjachjm.exe
    C:\WINDOWS\system32\j3231338.dll
    C:\WINDOWS\system32\uulkeano.exe
    C:\WINDOWS\system32\alt.exe
    C:\Documents and settings\All Users\Application Data\ytgloxyp.exe
    C:\WINDOWS\system32\lfhs76ghf.dll
    Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

    Select "All Files".

    Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

    If your computer does not restart automatically, please restart it manually.

    Restart your computer to the safe mode:
    • Restart your computer
    • Start tapping the F8 key when the computer restarts.
    • When the start menu opens, choose Safe mode
    • Press Enter. The computer then begins to start in Safe mode.


    Run ATF Cleaner
    • Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.

    Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
    • Click on Scanner on the toolbar.
    • Click on the Settings tab.
      • Under How to act?
        • Click on Recommended Action and choose Quarantine from the popup menu.
      • Under How to scan?
        • All checkboxes should be ticked.
      • Under Possibly unwanted software:
        • All checkboxes should be ticked.
      • Under Reports:
        • Select Automatically generate report after every scan and uncheck Only if threats were found.
      • Under What to scan?
        • Select Scan every file.
    • Click on the Scan tab.
    • Click on Complete System Scan to start the scan process.
    • Let the program scan the machine.
    • When the scan has finished, follow the instructions below.
      IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
      • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
      • At the bottom of the window click on the Apply all Actions button. (3)
    • When done, click the Save Scan Report button. (4)
      • Click the Save Report as button.
      • Save the report to your Desktop.
    • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
    Reboot in Normal Mode.

    ================

    When you're ready, please post the following logs to here:
    - AVG's report
    - a fresh HijackThis log
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  6. #16
    Junior Member
    Join Date
    May 2007
    Posts
    12

    Default

    Hello

    Ok, I was able to follow all of your instructions until I got to the part where I had to run the complete AVG system scan in Safe Mode. I kept getting the error, 'AVG Anti-Spyware 7.5 Error - Connection to service failed. Please reinstall AVG Anti-Spyware 7.5'. So every time I tried to reinstall (in Safe Mode), it asked me to reboot to complete the installation, and every time I rebooted it would not continue the installation. Then when trying to run AVG, I would keep getting the same error.

    So I tried to run it in Normal Mode, and it worked. I ran into more trouble here, because for some reason, after the scan was complete, and I clicked on 'Apply all Actions' (btw, I was able to successfully Quarantine all threats), the 'Save Report' button was grayed out (i.e., it would not let me save). So I took some screenshots of the results and saved them as gif files. I have attached them to this post. Hopefully those screenshots contain the information you need. If not, I can run the scan again; however, if you can please look at AVG_settings.gif and let me know if I did anything wrong, that would be helpful before running the scan again.

    Here is my HijackThis log...

    Logfile of HijackThis v1.99.1
    Scan saved at 18:27, on 2007-06-04
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\SYSTEM32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\DMI\WIN32\bin\DellDmi.exe
    C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
    C:\Program Files\Dell\OpenManage\Client\DLT.exe
    C:\WINDOWS\system32\wex4962\EMCliSrv.exe
    C:\Program Files\Dell\OpenManage\Client\Iap.exe
    C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
    C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    C:\Program Files\Network Associates\VirusScan\mcshield.exe
    C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\Program Files\Utimaco\SafeGuard Easy\SgeClient.exe
    C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
    C:\WINDOWS\system32\SgLogPlayer.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\RCSERV.EXE
    C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\dmi\win32\bin\Win32sl.exe
    C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Apoint\Apoint.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
    C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
    C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
    C:\Program Files\iPass\iPassConnect iRAS\downloader\ipccheck.exe
    C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
    C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
    C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe
    C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe
    C:\Program Files\Apoint\Apntex.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Philips\Philips Lime Service\bin\LimeAlive.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Philips\Philips Lime Service\bin\Lime.exe
    C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe
    C:\PROGRA~1\MICROS~4\rapimgr.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\Nortel Networks\TunnelGuard\platforms\win32\TGIconApp.EXE
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis\Scanner.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://autoproxy4.atl.ce.philips.com:8081/pixs.pac
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 130.139.56.200:8080
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
    O4 - HKLM\..\Run: [iPCCheck] "C:\Program Files\iPass\iPassConnect iRAS\downloader\ipccheck.exe" /startup
    O4 - HKLM\..\Run: [lcfep] "C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe"
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [PhilipsDM] "C:\Program Files\Philips\Philips Device Manager\Bin\DeviceManager.exe"
    O4 - HKLM\..\Run: [SgeEcView] C:\Program Files\Utimaco\SafeGuard Easy\Ecview.exe
    O4 - HKLM\..\Run: [EdWizard] C:\Program Files\Utimaco\SafeGuard Easy\EdWizard.exe as
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [PhilipsLime] "C:\Program Files\Philips\Philips Lime Service\bin\LimeAlive.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKCU\..\Run: [SpriteService] "C:\Program Files\Sprite Software\Sprite Backup\SpriteService.exe"
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: TunnelGuard Tray Monitor.lnk = ?
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english...an_unicode.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} (MSN Money Charting) - http://www.moneycentral.msn.com/cabs/pmupd806.exe
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor...fo/webscan.cab
    O16 - DPF: {B20D9D6A-0DEC-4D76-9BEF-175896006B4A} (RptViewerAX Class) - http://pww.webi.atl.ce.philips.com/w...ptVieweren.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://amaevents.webex.com/client/T...nt/ieatgpc.cab
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = code1.emi.philips.com
    O17 - HKLM\Software\..\Telephony: DomainName = code1.emi.philips.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = code1.emi.philips.com
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = code1.emi.philips.com,atl.ce.philips.com,knx.ce.philips.com,diamond.philips.com
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = code1.emi.philips.com,atl.ce.philips.com,knx.ce.philips.com,diamond.philips.com
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: NotLog - C:\WINDOWS\SYSTEM32\SGLogEx.dll
    O20 - Winlogon Notify: SGLogNotification - C:\WINDOWS\SYSTEM32\SGLogNotification.dll
    O23 - Service: ActionAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
    O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DellDmi - Dell Computer Corporation - C:\DMI\WIN32\bin\DellDmi.exe
    O23 - Service: DEventAgent - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
    O23 - Service: DLT - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\DLT.exe
    O23 - Service: EMCliSrv - Express Metrix - C:\WINDOWS\system32\wex4962\EMCliSrv.exe
    O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Nortel Networks\VPNClient\Extranet_serv.exe
    O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Client\Iap.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPassConnectEngine - iPass - C:\Program Files\iPass\iPassConnect iRAS\iPassConnectEngine.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: SafeGuard Easy Client (SgeClient) - Unknown owner - C:\Program Files\Utimaco\SafeGuard Easy\SgeClient.exe
    O23 - Service: SafeGuard Easy Control (SgeCtl) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\SgeCtl.exe
    O23 - Service: SafeGuard SGLOG Player (SgLogPlayer) - Utimaco Safeware AG - C:\WINDOWS\system32\SgLogPlayer.exe
    O23 - Service: Tivoli Remote Control Service (TME10RC) - TIVOLI Systems - C:\WINDOWS\RCSERV.EXE
    O23 - Service: Nortel Networks TunnelGuard (tunnelguardservice) - Alexandria Software Consulting - C:\Program Files\Nortel Networks\TunnelGuard\CueAgent_srv.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
    O23 - Service: Win32Sl - Intel - C:\dmi\win32\bin\Win32sl.exe
    O23 - Service: SafeGuard Easy Workstation Server (WksCfgSrv) - Utimaco Safeware AG - C:\Program Files\Utimaco\SafeGuard Easy\WksCfgSrv.exe

    Thanks!

  7. #17
    Junior Member
    Join Date
    May 2007
    Posts
    12

    Default better images

    I did not realize the proportion constraints until after I uploaded the gifs, which then became jpegs and are illegible, so I have created a zip file for you to view the results..it only contains AVG_quarantine.gif and AVG_scan.gif, and I could not include AVG_settings.gif, because of the max filesize; however, I more than triple-checked and made sure that I followed your instructions (especially the one about changing the Reports section to 'Automatically generate report after every scan'). I did this check after I quarantined the threats and could not save the report.

  8. #18
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hello

    You didn't do anything wrong. Just some conflict or bug.

    How is the computer running at the moment?

    Please do an online scan with Kaspersky WebScanner

    Click on Kaspersky Online Scanner

    You will be promted to install an ActiveX component from Kaspersky, Click Yes.
    • The program will launch and then begin downloading the latest definition files:
    • Once the files have been downloaded click on NEXT
    • Now click on Scan Settings
    • In the scan settings make that the following are selected:
      • Scan using the following Anti-Virus database:
      • Extended (if available otherwise Standard)
      • Scan Options:
      • Scan Archives
        Scan Mail Bases
    • Click OK
    • Now under select a target to scan:
      • Select My Computer
    • This will program will start and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete it will display if your system has been infected.
      • Now click on the Save as Text button:
    • Save the file to your desktop.
    • Copy and paste that information in your next post.
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  9. #19
    Junior Member
    Join Date
    May 2007
    Posts
    12

    Default

    I don't get any random pop-ups anymore, and my system clock in the taskbar is displaying correctly now; however, it still take 20 seconds or so from the time I launch a browser (e.g., IE) until when it shows any content..it's like it freezes during that time.

    Here is the Kaspersky Report...looks like I still have some things going on that haven't been contained..

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    2007-06-05 3:42
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.83.0
    Kaspersky Anti-Virus database last update: 5/06/2007
    Kaspersky Anti-Virus database records: 340022
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - Folders:
    C:\

    Scan Statistics:
    Total number of scanned objects: 98661
    Number of viruses found: 7
    Number of infected objects: 17 / 0
    Number of suspicious objects: 0
    Duration of the scan process: 01:42:09

    Infected Object Name / Virus Name / Last Action
    C:\Application_Data\McAfee\Quarantine\404-3[1].htm.Vir Object is locked skipped
    C:\Application_Data\McAfee\Quarantine\arc0000.tmp.Vir Object is locked skipped
    C:\Application_Data\Notes\bookmark.nsf Object is locked skipped
    C:\Application_Data\Notes\Cache.NDK Object is locked skipped
    C:\Application_Data\Notes\desktop6.ndk Object is locked skipped
    C:\Application_Data\Notes\IBM_TECHNICAL_SUPPORT\console.log Object is locked skipped
    C:\Application_Data\Notes\log.nsf Object is locked skipped
    C:\Application_Data\Notes\mail.box Object is locked skipped
    C:\Application_Data\Notes\NAMES.NSF Object is locked skipped
    C:\Application_Data\Notes\~notes.lck Object is locked skipped
    C:\DMI\WIN32\MifDB\errors.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-03162007-130208.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_USDATLPER4NB776.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_USDATLPER4NB776.log Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\AccessProtectionLog.txt Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\BufferOverflowProtectionLog.txt Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
    C:\Documents and Settings\All Users\Application Data\QSLLPSVCShare Object is locked skipped
    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    C:\Documents and Settings\usd00708\Application Data\$_hpcst$.hpc Object is locked skipped
    C:\Documents and Settings\usd00708\Application Data\Sprite PC Agent\SpriteLog.txt Object is locked skipped
    C:\Documents and Settings\usd00708\Cookies\index.dat Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_219.wmdb Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{7A2B8C9E-91E6-4171-9E4F-25A7F0B27928} Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\History\History.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\History\History.IE5\MSHist012007060520070606\index.dat Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\Temp\WCESLog.log Object is locked skipped
    C:\Documents and Settings\usd00708\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    C:\Documents and Settings\usd00708\NTUSER.DAT Object is locked skipped
    C:\Documents and Settings\usd00708\NTUSER.DAT.LOG Object is locked skipped
    C:\Program Files\Nortel Networks\TunnelGuard\log\TunnelGuard.log Object is locked skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\mllli.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\pee.exe.exe.vir Infected: Packed.Win32.Tibs.y skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\qyimhjag.dll.vir Infected: Trojan.Win32.BHO.bd skipped
    C:\QooBox\Quarantine\C\WINDOWS\system32\uonojovw.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088820.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088822.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088823.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.fp skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088824.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088899.exe Infected: Packed.Win32.Tibs.y skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088901.dll Infected: Trojan.Win32.BHO.bd skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP474\A0088902.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.kb skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP477\A0091415.exe Infected: Packed.Win32.Tibs.y skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP477\A0091416.dll Infected: Trojan-Clicker.Win32.Small.mw skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP477\A0091417.dll Infected: Trojan-Clicker.Win32.Small.mw skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP477\A0091418.dll Infected: Trojan-Clicker.Win32.Small.mw skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP477\A0091419.dll Infected: Trojan-Clicker.Win32.Small.mw skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP477\A0091420.dll Infected: Trojan-Downloader.Win32.Small.ddx skipped
    C:\System Volume Information\_restore{D98AB62C-7028-4E0F-A9C2-65B3C4B7405F}\RP478\change.log Object is locked skipped
    C:\WINDOWS\Debug\Netlogon.log Object is locked skipped
    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    C:\WINDOWS\Debug\WPD\wpdtrace.log Object is locked skipped
    C:\WINDOWS\SchedLgU.Txt Object is locked skipped
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    C:\WINDOWS\Sti_Trace.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
    C:\WINDOWS\system32\config\default.LOG Object is locked skipped
    C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    C:\WINDOWS\system32\config\SAM Object is locked skipped
    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY Object is locked skipped
    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
    C:\WINDOWS\system32\config\software.LOG Object is locked skipped
    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
    C:\WINDOWS\system32\config\system.LOG Object is locked skipped
    C:\WINDOWS\system32\h323log.txt Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    C:\WINDOWS\wiadebug.log Object is locked skipped
    C:\WINDOWS\wiaservc.log Object is locked skipped
    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    Scan process completed.

  10. #20
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hi again, it is looking clean now

    The leftovers were inside the system resotre which is easily cleaned. (see more info below)

    Now you can clean AVG's Quarantine:
    • Open AVG Anti-Spyware
    • Click Infections
    • Click Quarantine tab
    • Click Select all
    • Click Remove finally
    • Close the program

    You can remove the tools we used.

    =============

    Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:


    Stay clean and be safe
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •