1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

netcmd.exe [HJT log]

Discussion in 'Malware and Virus Removal Archive' started by mario, 2006/12/17.

  1. 2006/12/17
    mario

    mario Well-Known Member Thread Starter

    Joined:
    2003/02/15
    Messages:
    193
    Likes Received:
    0
    AVG detected netcmd.exe, which was in the system32 file, as a trojan and I did put it in the vault, Now everytime i boot the computer I get an error message saying that netcmd (obviously) was not found. I would like to know with which programe is this exe file associated with so that I can stop it starting on boot up since running msconfig I found no programes related to this file, thank you,

    mario
     
  2. 2006/12/17
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    I suspect you have an unwanted guest on your computer ......

    Please download HijackThis through Quicklinks in my signature and save it to a folder on your hard drive, say C:\HJT - not to the Desktop or a temporary location. When entries are fixed with HJT a backup is made to the folder from which HJT is run and this must be in a permanent location.

    Open the folder in which you placed HJT and double click on hijackthis.exe and select Scan and save a log file - this will be saved in the folder from which you ran HJT.

    Post the log (copy/paste) here.

    I have moved your thread to the Removing Spyware & Viruses forum.
     

  3. to hide this advert.

  4. 2006/12/17
    mario

    mario Well-Known Member Thread Starter

    Joined:
    2003/02/15
    Messages:
    193
    Likes Received:
    0
    this is the result from hijackthis scan:
    Logfile of HijackThis v1.99.1
    Scan saved at 5:19:19 PM, on 12/17/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0011)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    D:\PROGRA~3\Grisoft\AVG7\avgamsvr.exe
    D:\PROGRA~3\Grisoft\AVG7\avgupsvc.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    D:\PROGRA~3\Grisoft\AVG7\avgemc.exe
    D:\Program Files\DU Meter\DUMeter.exe
    D:\PROGRA~3\Grisoft\AVG7\avgcc.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\WINDOWS\system32\ctfmon.exe
    D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
    D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe
    C:\WINDOWS\system32\svchost.exe
    D:\PROGRA~3\Grisoft\AVG7\avgfwsrv.exe
    D:\Program Files\YPOPs\YPOPs.exe
    D:\Program Files\IncrediMail\bin\IncMail.exe
    D:\PROGRA~3\INCRED~1\bin\IMApp.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    D:\Program Files\Mass Downloader\massdown.exe
    D:\My downloads\hijackthis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    O2 - BHO: IE 4.x-6.x BHO for Internet Download Accelerator - {2A646672-9C3A-4C28-9A7A-1FB0F63F28B6} - (no file)
    O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O2 - BHO: IECatcher Class - {B930BA63-9E5A-11D3-A288-0000E80E2EDE} - D:\PROGRA~3\MASSDO~1\MDHELPER.DLL
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - D:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
    O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - D:\Program Files\Siber Systems\AI RoboForm\roboform.dll
    O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe "
    O4 - HKLM\..\Run: [DU Meter] D:\Program Files\DU Meter\DUMeter.exe
    O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~3\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [RoboForm] "D:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe "
    O4 - Startup: YPOPs.lnk = ?
    O8 - Extra context menu item: + &Mass Downloader: download this file - D:\Program Files\Mass Downloader\Add_Url.htm
    O8 - Extra context menu item: + Mass Downloader: download &All files - D:\Program Files\Mass Downloader\Add_All.htm
    O8 - Extra context menu item: Customize Menu - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O8 - Extra context menu item: Fill Forms - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O8 - Extra context menu item: RoboForm Toolbar - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O8 - Extra context menu item: Save Forms - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - D:\Program Files\Mass Downloader\massdown.exe
    O9 - Extra 'Tools' menuitem: &Mass Downloader - {0FD01980-CCCB-11D3-80D4-0000E80E2EDE} - D:\Program Files\Mass Downloader\massdown.exe
    O9 - Extra button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra 'Tools' menuitem: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
    O9 - Extra button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra 'Tools' menuitem: Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
    O9 - Extra button: Customize - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O9 - Extra 'Tools' menuitem: Customize Menu - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
    O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - D:\Program Files\Paltalk Messenger\Paltalk.exe
    O9 - Extra button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra 'Tools' menuitem: RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - file://D:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
    O9 - Extra button: Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: &Internet Download Accelerator - {9819CC0E-9669-4D01-9CD7-2C66DA43AC6C} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - d:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - d:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\avgfwafu.dll
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {210D0CBC-8B17-48D1-B294-1A338DD2EB3A} (VatCtrl Class) - http://icsgozo.no-ip.com/VatDec.cab
    O16 - DPF: {A8482EAF-A1F3-4934-AE3F-56EB195A50BF} (DeskUpdate - Activex Control) - http://support.fujitsu-siemens.de/DeskUpdate/isapi/activex.cab
    O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://88.203.50.32:2000/activex/RACtrl.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0B17171E-BF34-4C47-8280-7BC05D5B07C7}: NameServer = 192.168.1.254
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~3\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~3\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\PROGRA~3\Grisoft\AVG7\avgemc.exe
    O23 - Service: AVG Firewall (AVGFwSrv) - GRISOFT, s.r.o. - D:\PROGRA~3\Grisoft\AVG7\avgfwsrv.exe
    O23 - Service: Private Folder Service (prfldsvc) - Unknown owner - D:\Program Files\Microsoft Private Folder 1.0\PrfldSvc.exe
     
  5. 2006/12/17
    mario

    mario Well-Known Member Thread Starter

    Joined:
    2003/02/15
    Messages:
    193
    Likes Received:
    0
    after running spybot, ad-aware se pro and regcure it seems that the problem has gone (no error message on bootup). but now AVG detected also netconfig.exe in windows folder as trojan which I moved to vault but I am not sure if this is a windows file or trojan (Trojan horse PSW Generic2.UWL)as detected by AVG
     
  6. 2006/12/17
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Please wait for our resident security analyst to respond :)
     
  7. 2006/12/17
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Hi Mario.

    Nothing obvious in your log, but apparently something is lurking. I'd suggest a couple of online scans to verify what AVG is telling you.

    Also, one question, do you know what the service 'OdysseyClient' refers to? I can't seem to find anything conclusive on it other than it's in lots of logs, but no description.

    Here are the online scans:
    Panda ActiveScan
    • Click the [Scan your PC] button. ( You may have to disable any pop up blockers)
    • Then press the green [Check Now] button.
    • Enter your country and state along with a valid email address.
    • Allow the ActiveX install, it may be a few minutes for all components. (For XP SP 2 watch for the yellow bar at the top of IE)
    • Once installation is complete you will need to select a device to scan. Please select 'My Computer' and the scan will begin.
    • Once the scan is done, click the 'See report' button, then the 'save report' button. Be sure to save the log file created in a place easy for you to find. Your desktop is easiest

    Kaspersky Online Scanner

    Click on Kaspersky Online Scanner icon.
    Accept the Kaspersky agreement and the program will load.
    You will then be prompted to install an ActiveX component from Kaspersky, click Yes

    The program will then begin downloading the latest definition files. This will take a few minutes, even with hi-speed.
    Once the files have been downloaded click on Next

    Now click on [Scan Settings] button.
    In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended (if available otherwise Standard)
    • Scan Options:
      Scan Archives
      Scan Mail Bases
    Click OK

    Now under the Please select a target to scan:
    Select My Computer

    The program will begin the scanning process.
    The scan will take a while so be patient and let it run.
    Once the scan is complete it will display if your system has been infected.
    Then click on the [Save as Text] button
    Save the file to your desktop.

    Copy and paste that information in your next post for me to review.

    (Please edit out any 'cookie', 'Recyler folder' and 'System Volume Information Folder' references from both logs)
     
  8. 2006/12/17
    mario

    mario Well-Known Member Thread Starter

    Joined:
    2003/02/15
    Messages:
    193
    Likes Received:
    0
    OdysseyClient was a program I had used to manage my wireless connection instead of windows but had uninstalled it some time ago. I tried to do the online scans with Panda and Kaspersky but encountered some problems. Panda opened a popup asking for my country and email address but when I click on Free online scan nothing happens, and Kaspersky the same a pop window appeared asking to accept or decline, which I accepted then accepted also to install the activex but nothing happened it remained in the same page no scanning and nowhere to click :confused:

    Maybe I will try later :( and post results
     
  9. 2006/12/17
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    ActiveScan does occasionally hiccup.

    Not sure what happened with KAV tho. Trying later may work.
     
  10. 2006/12/19
    mario

    mario Well-Known Member Thread Starter

    Joined:
    2003/02/15
    Messages:
    193
    Likes Received:
    0
    I still did not manage to run those online scanners but managed with Trend micro online scanner and found no infection or anything else. It seems that no viruses or trojans are detected now and my initial problem seems to have gone now since even in the boot up the error that netcmd.exe is not found is not popping up, and a search for it on my computer is giving no results now.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.