1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Google Redirect Issue

Discussion in 'Malware and Virus Removal Archive' started by hockeypuck, 2007/06/28.

  1. 2007/06/28
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    I'm having the same exact problem

    And I can't seem to figure out how to fix it. I tried some of the things suggested in previous posts, still having the problem. Here is my HiJackThis log

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 11:35:37 PM, on 6/28/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\bcmntray.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\AOL\1145848184\ee\AOLSoftware.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\Luke\Desktop\HiJackThis_v2.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {3DC4BBB3-4A5C-43A7-8070-82CE4D6E3C6B} - c:\windows\system32\enmgecao.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll
    O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
    O2 - BHO: (no name) - {D6A37492-C8F1-4D38-ABB3-A7D8113ABB60} - c:\windows\system32\cbjacbj.dll
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145848184\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227A755E9C2933154389A
    O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: ghqtijez - C:\WINDOWS\SYSTEM32\cbjacbj.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 5298 bytes
     
  2. 2007/06/29
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Disable System Restore.

    follow these instructions

    Use HjT to get rid of:

    O2 - BHO: (no name) - {3DC4BBB3-4A5C-43A7-8070-82CE4D6E3C6B} - c:\windows\system32\enmgecao.dll
    O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll
    cbjacbj.dll
    O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
    O2 - BHO: (no name) - {D6A37492-C8F1-4D38-ABB3-A7D8113ABB60} - c:\windows\system32\cbjacbj.dll
    O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu11.exe 61A847B5BBF72813338B2B27128065E9C084320161C4661227 A755E9C2933154389A
    O4 - HKLM\..\Run: [startdrv] C:\WINDOWS\Temp\startdrv.ex
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: ghqtijez - C:\WINDOWS\SYSTEM32\cbjacbj.dll

    Run Disk Cleanup and check ALL itemes in the list: start > programs > accessories > system tools > disk cleanup

    reboot, rescan w/ HjT & post a new log

    It appears that you do not have an antivirus program? I suggest you get one and use it regularly. The AOL free antivirus is very good, it's based on the kapersky scanning engine. Get it here:
    http://www.activevirusshield.com/antivirus/freeav/index.adp?
     
    Last edited: 2007/06/29

  3. to hide this advert.

  4. 2007/06/30
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    That seems to have fixed the problem. Thanks Tony.

    Logfile of Trend Micro HijackThis v2.0.0 (BETA)
    Scan saved at 10:04:43 AM, on 6/30/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\savedump.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\WLTRYSVC.EXE
    C:\WINDOWS\System32\bcmwltry.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\WINDOWS\system32\bcmntray.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\AOL\1145848184\ee\AOLSoftware.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Digital Line Detect\DLG.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Luke\Desktop\HiJackThis_v2.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {3DC4BBB3-4A5C-43A7-8070-82CE4D6E3C6B} - c:\windows\system32\enmgecao.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: (no name) - {D6A37492-C8F1-4D38-ABB3-A7D8113ABB60} - c:\windows\system32\cbjacbj.dll
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\bcmntray
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe "
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1145848184\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe "
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O20 - Winlogon Notify: ghqtijez - C:\WINDOWS\SYSTEM32\cbjacbj.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
    O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

    --
    End of file - 4798 bytes
     
  5. 2007/06/30
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    almost fixed...
    Reboot & try to find these files and delete them:
    c:\windows\system32\enmgecao.dll
    c:\windows\system32\cbjacbj.dll

    Have you installed an antivirus program?
     
  6. 2007/06/30
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    Tony, is there any chance that what you had me remove affected Windows Explorer? I keep getting the following message on my screen ever since fixing the IE hijacking/redirect problem

    "Windows Explorer has encountered a problem and needs to close. We are sorry for the inconvenience."

    Nothing else is really affected, the computer simply seems to semi-reboot after the error message and everything from then on out is fine, but it is obviously annoying. Thoughts anyone?
     
  7. 2007/06/30
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    I found both of those files, but I can't delete them because the whole access denied, file may be in use, etc., etc. stuff.
     
  8. 2007/06/30
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    I went with the Active Virus Shield program you recommended.
     
  9. 2007/07/01
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
  10. 2007/07/01
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    Ran a full system scan, program deleted a bunch of malicious stuff. I also deleted all the values and registries suggested in the symantec article.

    I'm still unable to delete the two files you recommended deleting because of the write protected/in use stuff. Also, windows explorer keeps "encountering a problem and needs to close." I can't seem to fix that either.
     
  11. 2007/07/02
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    Download Combofix, saving it to your desktop.
    http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    Double click combofix.exe Follow the prompts.
    Don't click on the window while the fix is running, because that will cause your system to hang.

    When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
    Post the contents of that log in your next reply, along with a new HijackThis log (you may need to break it up into two or more posts).
    Please do NOT post the ComboFix-quarantined-files.txt unless I ask you to.

    Download ATF Cleaner by Atribune and save it to your Desktop.
    http://www.atribune.org/ccount/click.php?id=1
    Double click ATF-Cleaner.exe to run the program.
    Check the boxes to the left of:

    Windows Temp
    Current User Temp
    All Users Temp
    Temporary Internet Files
    Prefetch
    Java Cache
    Recycle bin

    The rest are optional - if you want it to remove everything check "Select All ".
    Finally, click Empty Selected. When you get the "Done Cleaning" message, click OK.
    Reboot.
     
  12. 2007/07/03
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    ComboFix 07-06-18.2 - C:\Documents and Settings\Luke\Desktop\ComboFix.exe
    "Luke" - 2007-07-03 9:12:29 - Service Pack 2 NTFS


    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


    C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon
    C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\domains.txt
    C:\DOCUME~1\LOCALS~1\APPLIC~1\netmon\log.txt
    C:\DOCUME~1\Luke\APPLIC~1\Microsoft\2236.dat
    C:\Documents and Settings\All Users.\documents\settings
    C:\Documents and Settings\All Users.\documents\settings\desktop.ini
    C:\Program Files\Common Files\{48A3D~1
    C:\Program Files\Common Files\{48A3D~1\system.dll.lzma
    C:\Program Files\Common Files\{48A3D~1\Update.exe.lzma
    C:\Program Files\Common Files\crosof~1.net
    C:\Program Files\stem32~1
    C:\Program Files\webhancer
    C:\Program Files\webhancer\Programs\webhdll.dll
    C:\WINDOWS\144.exe
    C:\WINDOWS\dembat.tm
    C:\WINDOWS\emdat.tm
    C:\WINDOWS\emdat.tmp
    C:\WINDOWS\ppatch~1
    C:\WINDOWS\system32\1.txt
    C:\WINDOWS\system32\2.txt
    C:\WINDOWS\system32\5_exception.nls
    C:\WINDOWS\system32\cbjacbj.dll
    C:\WINDOWS\system32\cbjacbj.dll.bak
    C:\WINDOWS\system32\drivers\xrhmeizc.sys
    C:\WINDOWS\system32\info.txt
    C:\WINDOWS\system32\svcp.csv
    C:\WINDOWS\system32\tsuninst.exe
    C:\WINDOWS\system32\vx.tll
    C:\WINDOWS\system32\winsub.xml
    C:\WINDOWS\system32\wnsapisu.exe
    C:\WINDOWS\wr.txt
    C:\WINDOWS\ystem3~1


    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


    -------\LEGACY_CBVILNSN
    -------\LEGACY_INIEQMMI
    -------\LEGACY_RUNTIME
    -------\LEGACY_RUNTIME2
    -------\cbvilnsn
    -------\inieqmmi
    -------\RpcApi
    -------\runtime


    ((((((((((((((((((((((((( Files Created from 2007-06-03 to 2007-07-03 )))))))))))))))))))))))))))))))


    2007-07-03 09:12 49,152 --a------ C:\WINDOWS\nircmd.exe
    2007-07-01 21:40 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE
    2007-07-01 09:13 1,181 --a------ C:\WINDOWS\mozver.dat
    2007-06-30 22:33 <DIR> d-------- C:\WINDOWS\system32\PreInstall
    2007-06-30 22:30 43,352 --a------ C:\WINDOWS\system32\wups2.dll
    2007-06-30 22:30 <DIR> d-------- C:\WINDOWS\system32\SoftwareDistribution
    2007-06-30 22:01 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    2007-06-30 19:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
    2007-06-30 19:42 <DIR> d-------- C:\99324cfb91fe26e50088
    2007-06-30 19:31 <DIR> d-------- C:\Program Files\Firefox
    2007-06-29 08:31 33,536 --a------ C:\WINDOWS\system32\drivers\runtime2.sys
    2007-06-28 23:12 6,535 --a------ C:\dnsbak.reg
    2007-06-28 07:39 684,567 --a------ C:\WINDOWS\system32\libeay32.dll
    2007-06-28 07:39 147,729 --a------ C:\WINDOWS\system32\libssl32.dll
    2007-06-28 07:36 92,672 --a------ C:\WINDOWS\system32\bxfzrlxm.dll
    2007-06-28 07:36 750,592 --a------ C:\WINDOWS\system32\npecrvxz.dll
    2007-06-28 07:36 65,024 --a------ C:\WINDOWS\system32\enmgecao.dll
    2007-06-28 07:36 42,496 --a------ C:\WINDOWS\system32\gxrbnzzk.dll
    2007-06-28 07:36 39,424 --a------ C:\WINDOWS\system32\yyaymfiy.dll
    2007-06-28 07:36 122,368 --a------ C:\WINDOWS\system32\stzyuzlc.dll


    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

    2007-07-01 01:38:29 -------- d-----w C:\Program Files\Online Services
    2007-07-01 01:38:18 -------- d-----w C:\Program Files\Windows NT
    2007-05-11 04:18:11 -------- d-----w C:\Program Files\Tarbox
    2007-04-17 02:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
    2007-04-17 02:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
    2007-04-17 02:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
    2007-04-17 02:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
    2007-04-17 02:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
    2007-04-17 02:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
    2007-04-17 02:43:44 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
    2006-09-07 12:24:27 88 -csh--r C:\WINDOWS\system32\209C994BC5.sys
    2006-09-07 12:24:27 3,350 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys


    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14 01:56]
    {3DC4BBB3-4A5C-43A7-8070-82CE4D6E3C6B}=c:\windows\system32\enmgecao.dll [2007-06-29 08:34]
    {5CA3D70E-1895-11CF-8E15-001234567890}=C:\WINDOWS\system32\dla\tfswshx.dll [2004-12-06 02:05]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SunJavaUpdateSched "= "C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 03:48]
    "SynTPEnh "= "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-11-29 05:56]
    "SigmatelSysTrayApp "= "stsystra.exe" [2005-09-10 00:19 C:\WINDOWS\stsystra.exe]
    "DVDLauncher "= "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 17:19]
    "ISUSPM Startup "= "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44]
    "ISUSScheduler "= "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44]
    "MSKDetectorExe "= "C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-12 20:05]
    "HostManager "= "C:\Program Files\Common Files\AOL\1145848184\ee\AOLSoftware.exe" [2006-05-09 20:24]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe "= "C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00]
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
    inieqmmi


    Contents of the 'Scheduled Tasks' folder
    2007-07-03 06:06:00 C:\WINDOWS\tasks\MP Scheduled Scan.job

    **************************************************************************

    catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-07-03 09:15:15
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    C:\WINDOWS\system32\Vmw45.sys

    scan completed successfully
    hidden files: 1

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Vmw45]
    "ImagePath "= "\SystemRoot\System32\Vmw45.sys "

    Completion time: 2007-07-03 9:15:55 - machine was rebooted
    C:\ComboFix-quarantined-files.txt ... 2007-07-03 09:15

    --- E O F ---
     
  13. 2007/07/03
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    OK, now post the ComboFix-quarantined-files.txt and a new HjT log.
    And if these files still exist outside the quarantine then try to delete them:

    C:\WINDOWS\system32\bxfzrlxm.dll
    C:\WINDOWS\system32\npecrvxz.dl
    C:\WINDOWS\system32\npecrvxz.dll
    C:\WINDOWS\system32\enmgecao.dll
    C:\WINDOWS\system32\yyaymfiy.dll
    C:\WINDOWS\system32\stzyuzlc.dll
    c:\windows\system32\enmgecao.dll
    C:\WINDOWS\system32\Vmw45.sys

    Go to Start > Run > type regedit > OK
    Edit Menu > Find > copy+paste
    {3DC4BBB3-4A5C-43A7-8070-82CE4D6E3C6B}
    if exists then right click the opened folder on left & select "delete "
     
  14. 2007/07/04
    hockeypuck

    hockeypuck Inactive Thread Starter

    Joined:
    2007/06/28
    Messages:
    8
    Likes Received:
    0
    I was able to delete all of those files. Here is the quarantine log

    Code:
    2006-07-21 18:55      127578    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\tsuninst.exe.vir
    2006-11-16 04:36      114688    --a------    C:\Qoobox\Quarantine\C\Program Files\webHancer\Programs\webhdll.dll.vir
    2006-11-30 02:16      0    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\emdat.tm.vir
    2006-11-30 02:16      0    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\emdat.tmp.vir
    2006-11-30 02:16      1    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\system32\vx.tll.vir
    2006-11-30 02:16      178    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\system32\svcp.csv.vir
    2006-11-30 02:16      4    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\system32\winsub.xml.vir
    2006-11-30 02:18      1008    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\dembat.tm.vir
    2006-12-02 17:43      0    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\system32\1.txt.vir
    2006-12-02 17:43      0    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\system32\2.txt.vir
    2006-12-02 18:10      166    --a--c---    C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Documents\Settings\desktop.ini.vir
    2006-12-02 18:11      34168    --a--c---    C:\Qoobox\Quarantine\C\DOCUME~1\Luke\APPLIC~1\Microsoft\2236.dat.vir
    2007-03-04 00:42      3062    --a--c---    C:\Qoobox\Quarantine\C\Program Files\Common Files\{48A3D~1\system.dll.lzma.vir
    2007-03-04 00:42      7074    --a--c---    C:\Qoobox\Quarantine\C\Program Files\Common Files\{48A3D~1\Update.exe.lzma.vir
    2007-03-04 00:54      42    --a--c---    C:\Qoobox\Quarantine\C\DOCUME~1\LOCALS~1\APPLIC~1\NetMon\domains.txt.vir
    2007-03-04 00:54      490    --a--c---    C:\Qoobox\Quarantine\C\DOCUME~1\LOCALS~1\APPLIC~1\NetMon\log.txt.vir
    2007-03-17 21:08      223    --a--c---    C:\Qoobox\Quarantine\C\WINDOWS\system32\info.txt.vir
    2007-05-22 23:46      2    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\wnsapisu.exe.vir
    2007-05-22 23:52      548    --a------    C:\Qoobox\Quarantine\C\WINDOWS\wr.txt.vir
    2007-06-28 07:30      12416    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\xrhmeizc.sys.vir
    2007-06-28 07:30      73728    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\cbjacbj.dll.bak.vir
    2007-06-28 07:31      0    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\5_exception.nls.vir
    2007-06-28 07:35      73728    --a------    C:\Qoobox\Quarantine\C\WINDOWS\system32\cbjacbj.dll.vir
    2007-06-28 21:47      0    --a------    C:\Qoobox\Quarantine\C\WINDOWS\144.exe.vir
    2007-07-03 09:13      1034    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME.reg.cf
    2007-07-03 09:13      1084    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_INIEQMMI.reg.cf
    2007-07-03 09:13      1100    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME2.reg.cf
    2007-07-03 09:13      1132    --a------    C:\Qoobox\Quarantine\Registry_backups\LEGACY_CBVILNSN.reg.cf
    2007-07-03 09:13      2160    --a------    C:\Qoobox\Quarantine\Registry_backups\services_inieqmmi.reg.cf
    2007-07-03 09:13      270    --a------    C:\Qoobox\Quarantine\Registry_backups\services_RpcApi.reg.cf
    2007-07-03 09:13      750    --a------    C:\Qoobox\Quarantine\Registry_backups\services_runtime.reg.cf
    2007-07-03 09:14      149762    --a------    C:\Qoobox\Quarantine\catchme2007-07-03_ 91513.25.zip
    2007-07-03 09:14      501    --a------    C:\Qoobox\Quarantine\catchme.log
    2007-07-03 09:14      7928    --a------    C:\Qoobox\Quarantine\Registry_backups\services_cbvilnsn.reg.cf
    
    
    Folder PATH listing
    Volume serial number is 48A3-D1DE
    C:\QOOBOX
    \---Quarantine
        |   catchme.log
        |   catchme2007-07-03_ 91513.25.zip
        |   
        +---C
        |   +---Documents and Settings
        |   |   \---All Users
        |   |       \---Documents
        |   |           \---Settings
        |   |                   desktop.ini.vir
        |   |                   
        |   +---DOCUME~1
        |   |   +---LOCALS~1
        |   |   |   \---APPLIC~1
        |   |   |       \---NetMon
        |   |   |               domains.txt.vir
        |   |   |               log.txt.vir
        |   |   |               
        |   |   \---Luke
        |   |       \---APPLIC~1
        |   |           \---Microsoft
        |   |                   2236.dat.vir
        |   |                   
        |   +---Program Files
        |   |   +---Common Files
        |   |   |   \---{48A3D~1
        |   |   |           system.dll.lzma.vir
        |   |   |           Update.exe.lzma.vir
        |   |   |           
        |   |   \---webHancer
        |   |       \---Programs
        |   |               webhdll.dll.vir
        |   |               
        |   \---WINDOWS
        |       |   144.exe.vir
        |       |   dembat.tm.vir
        |       |   emdat.tm.vir
        |       |   emdat.tmp.vir
        |       |   wr.txt.vir
        |       |   
        |       \---system32
        |           |   1.txt.vir
        |           |   2.txt.vir
        |           |   5_exception.nls.vir
        |           |   cbjacbj.dll.bak.vir
        |           |   cbjacbj.dll.vir
        |           |   info.txt.vir
        |           |   svcp.csv.vir
        |           |   tsuninst.exe.vir
        |           |   vx.tll.vir
        |           |   winsub.xml.vir
        |           |   wnsapisu.exe.vir
        |           |   
        |           \---drivers
        |                   xrhmeizc.sys.vir
        |                   
        \---Registry_backups
                LEGACY_CBVILNSN.reg.cf
                LEGACY_INIEQMMI.reg.cf
                LEGACY_RUNTIME.reg.cf
                LEGACY_RUNTIME2.reg.cf
                services_cbvilnsn.reg.cf
                services_inieqmmi.reg.cf
                services_RpcApi.reg.cf
                services_runtime.reg.cf
                
    
     
  15. 2007/07/04
    TonyT

    TonyT SuperGeek Staff

    Joined:
    2002/01/18
    Messages:
    9,072
    Likes Received:
    400
    1. Turn off System Restore.
    Go to Start and right-click on *My Computer*.
    Click Properties.
    Click the System Restore tab.
    Put a Checkmark in the box next to "Turn off System Restore ".
    Click Apply, and then click OK.

    2. Reboot.

    3. rescan for malware
    Download, install, update & scan w/
    Adaware http://www.lavasoftusa.com/products/ad_aware_free.php
    Spybot Search & Destroy http://www.safer-networking.org/en/mirrors/index.html
    & if all ok goto 4.

    4. Turn ON System Restore.
    Go to Start and right-click on *My Computer*.
    Click Properties.
    Click the System Restore tab.
    Remove the checkmark next to "Turn off System Restore ".
    Click Apply, and then click OK.

    Post results and how ncomp is running now.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.