1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Another Broadcaster Virus/Trojan Help?

Discussion in 'Malware and Virus Removal Archive' started by rbgreen21, 2007/04/08.

  1. 2007/04/08
    rbgreen21

    rbgreen21 Inactive Thread Starter

    Joined:
    2007/04/08
    Messages:
    2
    Likes Received:
    0
    Having trouble with IE, broadcaster taking over my browser.

    Here is my log file of hijack?

    Logfile of HijackThis v1.99.1
    Scan saved at 11:54:43 PM, on 4/8/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\Ati2evxx.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\WINDOWS\system32\spoolsv.exe
    E:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    E:\WINDOWS\system32\inetsrv\inetinfo.exe
    E:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe
    E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    E:\WINDOWS\system32\Ati2evxx.exe
    E:\WINDOWS\Explorer.EXE
    E:\Program Files\Norton AntiVirus\navapsvc.exe
    E:\WINDOWS\system32\HPZipm12.exe
    E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    E:\WINDOWS\SOUNDMAN.EXE
    E:\Program Files\Microsoft SQL Server\MSSQL.2\Reporting Services\ReportServer\bin\ReportingServicesService.exe
    E:\PROGRA~1\NORTON~1\navapw32.exe
    E:\Program Files\Microsoft IntelliType Pro\type32.exe
    E:\Program Files\Microsoft IntelliPoint\point32.exe
    E:\Program Files\DIGStream\digstream.exe
    E:\Program Files\ESPNRunTime\DIGServices.exe
    E:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
    E:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
    E:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    E:\Program Files\iTunes\iTunesHelper.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
    E:\Program Files\Verizon\McciTrayApp.exe
    E:\Program Files\Iomega\Automatic Backup Pro\LiveSystem.exe
    E:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
    E:\WINDOWS\system32\ctfmon.exe
    E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    E:\Program Files\MSI\Core Center\CoreCenter.exe
    E:\Program Files\MSI\DigiCell\DigiCell.exe
    E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    E:\Program Files\PrintKey2000\Printkey2000.exe
    E:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    E:\Program Files\Canon\CAL\CALMAIN.exe
    E:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe
    E:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    E:\Program Files\iPod\bin\iPodService.exe
    E:\WINDOWS\System32\svchost.exe
    E:\WINDOWS\system32\zshp2600.exe
    E:\WINDOWS\system32\wscntfy.exe
    E:\WINDOWS\system32\HPZinw12.exe
    E:\Program Files\Internet Explorer\iexplore.exe
    E:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
    E:\Program Files\Microsoft Office\Office10\WINWORD.EXE
    E:\WINDOWS\system32\notepad.exe
    E:\Program Files\Internet Explorer\iexplore.exe
    C:\data\hijackthis_sfx.exe
    C:\data\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - E:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATIPTA] E:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] E:\PROGRA~1\SYMNET~1\SNDMon.exe
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NAV Agent] E:\PROGRA~1\NORTON~1\navapw32.exe
    O4 - HKLM\..\Run: [type32] "E:\Program Files\Microsoft IntelliType Pro\type32.exe "
    O4 - HKLM\..\Run: [IntelliPoint] "E:\Program Files\Microsoft IntelliPoint\point32.exe "
    O4 - HKLM\..\Run: [DIGStream] E:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [DIGServices] E:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files\Java\jre1.5.0_11\bin\jusched.exe "
    O4 - HKLM\..\Run: [Motive SmartBridge] E:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [RoxioDragToDisc] "E:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe "
    O4 - HKLM\..\Run: [Verizon_McciTrayApp] E:\Program Files\Verizon\McciTrayApp.exe
    O4 - HKCU\..\Run: [Iomega Automatic Backup Pro] "E:\Program Files\Iomega\Automatic Backup Pro\LiveSystem.exe" -s
    O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: CoreCenter.lnk = E:\Program Files\MSI\Core Center\CoreCenter.exe
    O4 - Global Startup: DigiCell.lnk = E:\Program Files\MSI\DigiCell\DigiCell.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Printkey2000.lnk = E:\Program Files\PrintKey2000\Printkey2000.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Verizon Central - {5B3FB261-CF72-4c66-B314-8E6FF9980307} - www.verizon.net (file missing)
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - E:\Program Files\WebEx\WebEx\350\atonecli.dll (HKCU)
    O9 - Extra 'Tools' menuitem: Start WebEx One-Click Meeting - {80947ADC-151D-490B-87F1-7C8CE1B46220} - E:\Program Files\WebEx\WebEx\350\atonecli.dll (HKCU)
    O15 - Trusted Zone: http://*.promsvr
    O15 - Trusted Zone: http://*.turbotax.com
    O15 - Trusted Zone: www.verizon.net
    O15 - Trusted Zone: *.verizon.net
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/MT...vehicles/2006/tacoma/key_features/ext360.html
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
    O16 - DPF: {871AA60B-D425-4784-AD09-6C2E63342CAD} (vzDLinkRouterUpgrade Class) - http://download.verizon.net/sfp/Cabs/dlink/webinstall/FrmUpDLink.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://freetrial.webex.com/client/T25L/webex/ieatgpc.cab
    O16 - DPF: {FA91DF8D-53AB-455D-AB20-F2F023E498D3} (RSClientPrint Class) - http://office/ReportServer/Reserved...033&UICulture=9&ReportStack=1&OpType=PrintCab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{5844D5E1-4107-42CB-A3F9-891CB17D67B9}: NameServer = 192.168.0.1
    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - E:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - E:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - E:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - E:\Program Files\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - E:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: Google Updater Service (gusvc) - Google - E:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - E:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - E:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: InstallShield Licensing Service - Macrovision - E:\Program Files\Common Files\InstallShield Shared\Service\InstallShield Licensing Service.exe
    O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate - Symantec Corporation - E:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: SQL Server FullText Search (MSSQLSERVER) (msftesql) - Unknown owner - E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\msftesql.exe" -s:MSSQL.1 -f:MSSQLSERVER (file missing)
    O23 - Service: SQL Server (MSSQLSERVER) (MSSQLSERVER) - Unknown owner - E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER (file missing)
    O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - E:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - E:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - E:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: SQL Server Agent (MSSQLSERVER) (SQLSERVERAGENT) - Unknown owner - E:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\SQLAGENT90.EXE" -i MSSQLSERVER (file missing)
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - E:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - E:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
     
    Last edited: 2007/04/09
  2. 2007/04/09
    rbgreen21

    rbgreen21 Inactive Thread Starter

    Joined:
    2007/04/08
    Messages:
    2
    Likes Received:
    0
    Can anyone help?

    Can anyone assist me.

    Thanks
     

  3. to hide this advert.

  4. 2007/04/09
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Hello and welcome to WindowsBBS Forums.

    This one sure is making the rounds all of a sudden.

    Not seeing much, pretty the same as some of the other threads, so lets try some looking around.

    Download Autoruns by Sysinternals from here and save it to your desktop.

    Extract the files to your desktop, open the Autoruns folder, and double-click autoruns.exe to run it.

    When the scan is finished from the toolbar, select the [Options] tab, then tick the 'Hide Microsoft Entries' option. Then hit the 'refresh' icon.

    Post the log here for me to view.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.