Hello,
I was on myspace (first mistake I suppose) using Mozilla and IE windows began popping up, and now my computer is infected wiith all sorts of viruses/spyware. I downloaded and ran AVG anti-virus and spyware, but each time I restart, the infections are back. I have followed all instructions in "before you post" section. Had to work hard to get the Kaspersky log-viruses seemed to infect it and could not run. Same with avg anti-virus. I have previously used Norton and AdAware, though I probably have not updated as I should. Please help! I will be heading to bed soon as it took all night last night to get Kaspersky to work, but will log in tomorrow morning (around 7am MST).
HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:09 PM, on 1/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Aegon\Updater\Updater.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
F3 - REG:win.ini: load=C:\WINDOWS\system32\jkkjk.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - (no file)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [Launcher] F:\setup.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [aca01c91] rundll32.exe "C:\WINDOWS\system32\ytdtdwrt.dll",b
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp .exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe" /minimized
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA2999] command /c del "C:\WINDOWS\system32\jkkjk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1060] cmd /c del "C:\WINDOWS\system32\jkkjk.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3803] command /c del "C:\WINDOWS\system32\jkkjk.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6672] cmd /c del "C:\WINDOWS\system32\jkkjk.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PiXPO] "C:\Program Files\ProPix Share\1.5\Pixpo.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-448539723-1801674531-682003330-1005\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Anastasia')
O4 - HKUS\S-1-5-21-448539723-1801674531-682003330-1005\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 (User 'Anastasia')
O4 - HKUS\S-1-5-21-448539723-1801674531-682003330-1005\..\Run: [Ooba] "C:\PROGRA~1\YSTEM~1\userinit.exe" -vt ndrv (User 'Anastasia')
O4 - HKUS\S-1-5-21-448539723-1801674531-682003330-1005\..\Run: [Mxdbxgsi] "C:\Documents and Settings\Anastasia N\My Documents\?icrosoft\?ti2evxx.exe" (User 'Anastasia')
O4 - HKUS\S-1-5-21-448539723-1801674531-682003330-1005\..\Run: [Dot1XCfg] C:\Program Files\Dot1XCfg\Dot1XCfg.exe (User 'Anastasia')
O4 - HKUS\S-1-5-21-448539723-1801674531-682003330-1005\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User 'Anastasia')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Toolbox Updater.lnk = C:\Program Files\Aegon\Updater\Updater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\npjpi160_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/...sh/swflash.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\AdvTools\NPROTECT.EXE
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
--
End of file - 8748 bytes
Kaspersky Log:
Scan My Computer
----------------
Scanned: 258856
Detected: 48
Untreated: 48
Start time: 1/29/2008 10:01:37 PM
Duration: 08:03:13
Finish time: 1/30/2008 6:04:50 AM
Signatures published: 1/29/2008 6:40:34 PM
Detected
--------
Status Object
------ ------
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: c:\windows\system32\jkkjk.exe
detected: adware not-a-virus:AdWare.Win32.PurityScan.gv File: c:\windows\system32\tup.dll//PE_Patch.PECompact//PecBundle//PECompact
detected: adware not-a-virus:AdWare.Win32.PurityScan.gt File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0082729.dll//PE_Patch.PECompact//PecBundle//PECompact
detected: adware not-a-virus:AdWare.Win32.ZenoSearch.ad File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0083872.dll
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084885.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084886.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fn File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084890.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084894.exe
detected: Trojan program Trojan-Downloader.Win32.Agent.gwe File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084902.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084913.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0084920.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0085907.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fn File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0085910.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0085914.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0085929.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP731\A0085932.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP732\A0085947.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP732\A0085952.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP732\A0085954.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP733\A0086015.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP733\A0086018.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086133.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086135.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086136.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086159.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086162.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086164.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086167.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086179.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP734\A0086183.exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP735\A0086208.exe
detected: adware not-a-virus:AdWare.Win32.PurityScan.gv File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP735\A0086212.dll//PE_Patch.PECompact//PecBundle//PECompact
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP736\A0086307.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP737\A0086320.exe
detected: adware not-a-virus:AdWare.Win32.PurityScan.gv File: C:\System Volume Information\_restore{818EB6AD-84C3-45E2-882E-A48453649B62}\RP737\A0086321.dll//PE_Patch.PECompact//PecBundle//PECompact
detected: Trojan program Trojan.Win32.Scapur.k File: C:\Program Files\Common Files\Yazzle1552OinAdmin.exe//PE_Patch.PECompact//PecBundle//PECompact
detected: adware not-a-virus:AdWare.Win32.PurityScan.gp File: C:\Program Files\Common Files\Yazzle1552OinUninstaller.exe//data0001
detected: Trojan program Trojan-Downloader.Win32.Adload.pr File: C:\Program Files\Dot1XCfg\Dot1XCfg .exe
detected: Trojan program Trojan.Java.ClassLoader.Dummy.a File: C:\Program Files\Norton AntiVirus\Quarantine\122C23D7.class//CryptFF
detected: Trojan program Trojan.Java.ClassLoader.c File: C:\Program Files\Norton AntiVirus\Quarantine\12304DD4.class//CryptFF
detected: malware Exploit.Java.ByteVerify File: C:\Program Files\Norton AntiVirus\Quarantine\59E31CF4.class//CryptFF
detected: Trojan program Trojan-Downloader.Java.OpenConnection.v File: C:\Program Files\Norton AntiVirus\Quarantine\7177607C.class//CryptFF
detected: adware not-a-virus:AdWare.Win32.ZenoSearch.ad File: C:\Program Files\Outerinfo\FF\components\FF.dll
detected: Trojan program Trojan.Win32.Agent.edq File: C:\Program Files\Temporary\kernInst.exe
detected: Trojan program Trojan-Downloader.Win32.PurityScan.fk File: C:\Program Files\?ystem\userinit .exe//PE_Patch.UPX//UPX
detected: Trojan program Trojan-Downloader.Win32.Agent.hvj File: C:\WINDOWS\b122.exe
detected: Trojan program Trojan-Dropper.Win32.Agent.dgo File: C:\WINDOWS\system32\ctfmon.exe.tmp
detected: Trojan program Trojan.Win32.Scapur.k File: C:\WINDOWS\system32\LDBC0.tmp//data0002//PE_Patch.PECompact//PecBundle//PECompact
Events
------
Time Name Status Reason
---- ---- ------ ------
1/29/2008 10:01:37 PM Running module: smss.exe\smss.exe ok scanned
Statistics
----------
Object Scanned Detected Untreated Deleted Moved to Quarantine Archives Packed files Password protected Corrupted
------ ------- -------- --------- ------- ------------------- -------- ------------ ------------------ ---------
Settings
--------
Parameter Value
--------- -----
Security Level Recommended
Action Prompt for action when the scan is complete
Run mode Manually
File types Scan all files
Scan only new and changed files No
Scan archives All
Scan embedded OLE objects All
Skip if object is larger than No
Skip if scan takes longer than No
Parse email formats No
Scan password-protected archives No
Enable iChecker technology Yes
Enable iSwift technology Yes
Record information about dangerous objects to program statistics Yes