1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Virus Files need deleting [HJT Log]

Discussion in 'Malware and Virus Removal Archive' started by Fayth, 2005/06/16.

Thread Status:
Not open for further replies.
  1. 2005/06/16
    Fayth

    Fayth Inactive Thread Starter

    Joined:
    2005/06/16
    Messages:
    2
    Likes Received:
    0
    Yesterday a bunch of virus things popped out, so now I'm kind of freaking.. Nothing can find any viruses, although I did go into my temporary internet files and found trojan.moo

    Here's the logs from Norton and from Hijack this

    Category: Virus alerts
    Date,Feature,Virus Name,Action Taken,Item Type,Target,Suspicious Action,User Name,Computer Name,Details
    6/16/2005 2:41:36 AM,Auto-Protect,Trojan.ByteVerify,Automatically deleted,File,N/A,N/A,Nick,NICK,Source: C:\Documents and Settings\Nick1\Local Settings\Temporary Internet Files\Content.IE5\WHKFWVGT\count[1].jar
    6/16/2005 2:41:36 AM,Auto-Protect,Trojan.Moo,Access denied,File,N/A,N/A,Nick,NICK,Source: C:\Documents and Settings\Nick1\Local Settings\Temporary Internet Files\Content.IE5\6HUT41MD\payload[1].ani
    6/16/2005 2:41:35 AM,Auto-Protect,Trojan.Moo,Repair failed,File,N/A,N/A,Nick,NICK,Source: C:\Documents and Settings\Nick1\Local Settings\Temporary Internet Files\Content.IE5\6HUT41MD\payload[1].ani
    6/16/2005 2:31:44 AM,Auto-Protect,MHTMLRedir.Exploit,Access denied,File,N/A,N/A,Nick,NICK,Source: C:\Documents and Settings\Nick1\Local Settings\Temporary Internet Files\Content.IE5\YTUPY5QR\bcdlmkpjnq.mjcmgu.kchj-D-B-B-I.jhqo[1].wspbemz
    6/16/2005 2:31:44 AM,Auto-Protect,MHTMLRedir.Exploit,Repair failed,File,N/A,N/A,Nick,NICK,Source: C:\Documents and Settings\Nick1\Local Settings\Temporary Internet Files\Content.IE5\YTUPY5QR\bcdlmkpjnq.mjcmgu.kchj-D-B-B-I.jhqo[1].wspbemz
    6/16/2005 2:31:36 AM,Auto-Protect,MHTMLRedir.Exploit,Automatically deleted,File,N/A,N/A,Nick,NICK,Source: C:\Documents and Settings\Nick1\Local Settings\Temporary Internet Files\Content.IE5\WTIZMZW3\bcdlmkpjnq.mjcmgu.kchj-D-B-B-I.jhqo[1].wspbemz


    And the other


    Logfile of HijackThis v1.99.1
    Scan saved at 5:09:47 PM, on 6/16/2005
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\hidserv.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    D:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    D:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    C:\WINNT\system32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    D:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Common Files\Symantec Shared\SymTray.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    D:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\WINNT\system32\RUNDLL32.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    C:\WINNT\system32\ctfmon.exe
    D:\Program Files\Logitech\SetPoint\KEM.exe
    D:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
    C:\Program Files\Common Files\Symantec Shared\Nmain.exe
    C:\Program Files\Common Files\Symantec Shared\ccLgView.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    D:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
    C:\WINNT\system32\notepad.exe
    D:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\Nick1\LOCALS~1\Temp\Rar$EX07.594\HijackThis.exe

    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe "
    O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
    O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\KEM.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - D:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
    O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - D:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Speed Disk service - Symantec Corporation - D:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Any help is greatly appreciated.. Thanks so much
     
    Last edited: 2005/06/16
  2. 2005/06/16
    Fayth

    Fayth Inactive Thread Starter

    Joined:
    2005/06/16
    Messages:
    2
    Likes Received:
    0
    Okay,

    I set it to view hidden files, and I found some trojan.byteverify and junk in my folders.. :(

    And the .exploit from above..
     

  3. to hide this advert.

  4. 2005/06/17
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    Hello, welcome to the boards.
    Your HJT log is clean, however if you feel the need to use it again, unzip it to it's own folder, it works better that way, and you are prompted on this when it starts.
    To get rid of those files, go to Control Panel\Java, click on Delete Files on the bottom, in the new window all three boxes should be checked, then click on OK.
    Then go to Internet Options, click on Delete Files, make sure the box for 'offline content' is checked.
    Those bad files are there because of a failed attempt at infection, indicative of good security.
    Update your Java, there is a security problem with it's Java Webstart.
    http://www.windowsbbs.com/showthread.php?t=45549
    BTW, I edited your thread title to something more meaningful.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.