Amethystine
New member
I've tried to figure out whether or not I should post by seeing if there's a thread with the same problems as mine, but I can't tell if I should or not. So I'm just going to give it a shot and try posting.
As the title says, I can't use Task Manager anymore, which is what first alerted me that something was wrong. I also notice a bit of a refresh every 5 minutes or so, which coincides with a folder from C:\Program Files\Common Files named "{EC00B7F8-0477-1033-0329-040314010002}" being dumped into the Recycle Bin. (It begins to build up in there over time, as well.) The folder contains 2 files: "System.dll" and "Update" (update is an application, I'm not sure of the extension).
I have since gotten Spybot and used it many times (it runs on startup every time, now.) And it finds Command Service and Toolbar888-Smitfraud. It says it fixes Bar888 everytime, but says it can't fix Command and that I should restart my PC. But on the subsequent re-starts, it is still unable to deal with it, as well as finding Bar888 again.
I took the steps in the 'Before you Post' topic, and while in Safe Mode, Spybot couldn't get rid of 'Command' either.
Sorry for the long story, here are my logs:
eTrust Antivirus Web Scanner
Scan Results: 86382 files scanned. 17 viruses were detected.
File Infection Status Path
arc.zip-6c522c5b-5fce5073.zip>VerifierBug.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Counter.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Gummy.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Beyond.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Worker.class Java/Shinwow.M infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>GetAccess.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>Installer.class Java/Shinwow.AZ infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>NewSecurityClassLoader.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>NewURLClassLoader.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Matrix.class Java/Shinwow.W infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Counter.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Dummy.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Parser.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
astr.exe Win32/Starphish.A infected C:\Documents and Settings\Colin\
p.zip Win32/Alcan.I!ZIP infected C:\Program Files\outlook\
p.zip>Setup.exe Win32/Alcan.I infected C:\Program Files\outlook\
v.tmp Win32/Alcan.I infected C:\Program Files\outlook\
It said 'cannot cure' for all of them once I tried to 'Cure Files'
----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 5:54:40 AM, on 10/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\EPSON\ESM2\eEBSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\iTunes\iTunesHelper.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\system32\winlog.exe
C:\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\hijackthis\HijackThis.exe
C:\Program Files\Common Files\{EC00B7F8-0477-1033-0329-040314010002}\Update.exe
F1 - win.ini: run= C:\WESTWOOD\C&C95\INSTICON.EXE
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [QuickTime Task] "C:\QuickTime6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{EC00B7F8-0477-1033-0329-040314010002}] "C:\Program Files\Common Files\{EC00B7F8-0477-1033-0329-040314010002}\Update.exe" mc-110-12-0000137
O4 - HKLM\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: EPSON Background Monitor.lnk = C:\EPSON\ESM2\STMS.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52....apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Q29saW4gUGFya3M\command.exe (file missing)
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\EPSON\ESM2\eEBSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
Oddly enough, Bar888 wasn't in that scan. It normally appears in the 02 - BHOs.. although it might not be there right now because I JUST restarted and Spybot ran at startup and 'fixed' it. (Almost makes me want to go do things until it reappears, just to include it in the log for you guys. :sad: )
I also had an older version of Bearshare, which I (hopefully) got rid of the other day, when I saw it on that list of possibly infectious P2P programs.
Anyway, I hope I wasn't out of line, posting this here.
As the title says, I can't use Task Manager anymore, which is what first alerted me that something was wrong. I also notice a bit of a refresh every 5 minutes or so, which coincides with a folder from C:\Program Files\Common Files named "{EC00B7F8-0477-1033-0329-040314010002}" being dumped into the Recycle Bin. (It begins to build up in there over time, as well.) The folder contains 2 files: "System.dll" and "Update" (update is an application, I'm not sure of the extension).
I have since gotten Spybot and used it many times (it runs on startup every time, now.) And it finds Command Service and Toolbar888-Smitfraud. It says it fixes Bar888 everytime, but says it can't fix Command and that I should restart my PC. But on the subsequent re-starts, it is still unable to deal with it, as well as finding Bar888 again.
I took the steps in the 'Before you Post' topic, and while in Safe Mode, Spybot couldn't get rid of 'Command' either.
Sorry for the long story, here are my logs:
eTrust Antivirus Web Scanner
Scan Results: 86382 files scanned. 17 viruses were detected.
File Infection Status Path
arc.zip-6c522c5b-5fce5073.zip>VerifierBug.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Counter.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Gummy.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Beyond.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
arc.zip-6c522c5b-5fce5073.zip>Worker.class Java/Shinwow.M infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>GetAccess.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>Installer.class Java/Shinwow.AZ infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>NewSecurityClassLoader.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-678c1b03-29069d08.zip>NewURLClassLoader.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Matrix.class Java/Shinwow.W infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Counter.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Dummy.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
load14.jar-5d2fff2a-5396e5c6.zip>Parser.class Java/ByteVerify!exploit infected C:\Documents and Settings\Colin\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
astr.exe Win32/Starphish.A infected C:\Documents and Settings\Colin\
p.zip Win32/Alcan.I!ZIP infected C:\Program Files\outlook\
p.zip>Setup.exe Win32/Alcan.I infected C:\Program Files\outlook\
v.tmp Win32/Alcan.I infected C:\Program Files\outlook\
It said 'cannot cure' for all of them once I tried to 'Cure Files'
----------------------------------------------
Logfile of HijackThis v1.99.1
Scan saved at 5:54:40 AM, on 10/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\EPSON\ESM2\eEBSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\iTunes\iTunesHelper.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\system32\winlog.exe
C:\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\hijackthis\HijackThis.exe
C:\Program Files\Common Files\{EC00B7F8-0477-1033-0329-040314010002}\Update.exe
F1 - win.ini: run= C:\WESTWOOD\C&C95\INSTICON.EXE
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [QuickTime Task] "C:\QuickTime6\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [{EC00B7F8-0477-1033-0329-040314010002}] "C:\Program Files\Common Files\{EC00B7F8-0477-1033-0329-040314010002}\Update.exe" mc-110-12-0000137
O4 - HKLM\..\Run: [IpWins] C:\Program Files\Ipwindows\ipwins.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: EPSON Background Monitor.lnk = C:\EPSON\ESM2\STMS.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52....apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Q29saW4gUGFya3M\command.exe (file missing)
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\EPSON\ESM2\eEBSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
Oddly enough, Bar888 wasn't in that scan. It normally appears in the 02 - BHOs.. although it might not be there right now because I JUST restarted and Spybot ran at startup and 'fixed' it. (Almost makes me want to go do things until it reappears, just to include it in the log for you guys. :sad: )
I also had an older version of Bearshare, which I (hopefully) got rid of the other day, when I saw it on that list of possibly infectious P2P programs.
Anyway, I hope I wasn't out of line, posting this here.