1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

A file that won't go away

Discussion in 'Malware and Virus Removal Archive' started by Newt, 2004/01/10.

Thread Status:
Not open for further replies.
  1. 2004/01/10
    Newt

    Newt Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Been trying to help out a friend with XP. He has a file (kazaa lite download thing) that won't allow itself to be deleted. In use by something even in safe mode.

    He sent a copy of a Hijack This log and I would love to have some of you folks who know this stuff better than I do take a look - see if you spot any baddies that need to go away.

    LOG:

    Logfile of HijackThis v1.97.7
    Scan saved at 22:43:26, on 09/01/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton Personal Firewall\NISUM.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Norton Personal Firewall\NISSERV.EXE
    C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
    C:\WINDOWS\System32\RunDll32.exe
    C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Kazaa Lite\kazaalite.kpp
    C:\Program Files\iISystem Wiper\SystemWiper.exe
    C:\Program Files\iISystem Wiper\SystemWiper.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Documents and Settings\Brian\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1.1\SDHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe "
    O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
    O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe
    O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe "
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
    O16 - DPF: ConferenceRoom Java Client - http://irc.axpi.net:8000/java/cr.cab
    O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac...supportutil.CAB
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212...meInstaller.exe
    O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestation.com/common/classes...ab?ver=1,1,0,30
    O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - http://webiqonline.com/WebIQ/bin/WebIQ.cab
    O16 - DPF: {5E943D9C-F8DC-4258-8E3F-A61BB3405A33} (ZingBatchAXDwnl Class) - http://www.imagestation.com/common/classes...ion=4,3,2,20802
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/76808a0...all/xscan53.cab
    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
    O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://offers.conten****ch.com/audit/inclu...uditControl.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
    O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{B8A9B457-A0BE-4BAB-B6BC-CCF9D2894B23}: NameServer = 195.92.195.94 195.92.195.95
     
    Newt,
    #1
  2. 2004/01/10
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Hi Newt
    You know im not a log read per say,, nor an XP person,, gee I wont allow any filesharing near this pc either..and ive no exp with kazza or kazza lite..

    First of have them unzip hijackthis and put in a permanate folder
    ie they ofen run it from wthin a zip program.. some even choose to open it instead of downloading gee..
    Zing looks suspious
    this one can go but do it with msconfig
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    I see no badware,, I would remove all 0-16's and disable a few things with msconfig..

    check in addremove for p2p something and uninstall it ,,er anything suspious

    I suppose you tried the obvious with kazza lite ?
    are you saying kazza lite wont uninstall ?
    install again and see if it will then uninstall
    and unchecking its startups then restarting the PC you still cant delete the files and the startups come back..
    I suppose youve seen the Kazza remover,, dont know what it would do with the lite version
    KazaaBegone at http://www.merijn.org/downloads.html

    be sure to coution them and download lspfix first

    Regards
    Lonny
     

  3. to hide this advert.

  4. 2004/01/10
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    I'm sure you have him do a full virus scan, but the 2 that are suspicious are smss.exe and lsass.exe. Even though these are legimate files, depending on their location, numerous worms create these.

    worm1
     
  5. 2004/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Newt
    I'll take another look at that log.
    Meanwhile, a couple of comments.
    There is an excellent utility to get rid of "prone to delete" files, called "MoveOnBoot ". It'll delete a file upon next reboot, so, it's for sure not being used by anything else. It's not free anymore, but, you still can download an earlier free version from
    THIS GERMAN SITE
    Then, Kazaa Lite doesn't exist anymore. Original Kazaa developers are suing Kazaa Lite maker over copyright issues, and Kazaa Lite was forced to shut down. How pathetic...someone tries to give you a program without a spyware (Yes, I understand, Kazaa Lite developer, broke Kazaa code to remove that spyware), and that person is supposed to be a criminal, but original Kazaa, planting a spyware on your computer is perfectly alright. Well...
    Now, I'll take a look at that log....
     
  6. 2004/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    Not needed at the startup

    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    Not needed at the startup

    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    Definitely startup garbage

    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Kazaa Lite\kazaalite.kpp
    Both, not needed at the startup.

    C:\Program Files\iISystem Wiper\SystemWiper.exe
    Not needed at the startup

    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    Not needed at the startup.

    O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
    Not needed at the startup. It may cause some problems, if loaded.

    O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
    Shouldn't be in startup list. Uncheck.

    O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
    Not needed at the startup

    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
    Required only if you use Win2K/XP and login without admin privileges

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [KAZAA] "C:\Program Files\Kazaa Lite\kpp.exe" "C:\Program Files\Kazaa Lite\kazaalite.kpp" /SYSTRAY
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    Not needed at the startup

    O4 - HKLM\..\Run: [ZingSpooler] C:\Program Files\Common Files\Zing\ZingSpooler.exe
    Was used for a drag and drop program to upload pictures to www.zing.com but Zing has gone out of business. Now used for Sony ImageStation's upload photos to online albums. Your choice.

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    Unless you have the Spybot S&D option 'Lock homepage from changes' active, have HijackThis fix this.

    Other, then those Startup issues, I can't see any "bad guys" there.
     
  7. 2004/01/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    BTW
    What is that file name? Loooong file name?
     
  8. 2004/01/10
    indmusic

    indmusic Well-Known Member

    Joined:
    2002/10/23
    Messages:
    143
    Likes Received:
    3
    Just checking, but have you tried deleting the file from the
    Kazaa program itself? Was it a complete download?
    You may want to snoop around in Kazaa and delete it from
    there. I don't use Kazaa or Klite so that's as much help I can
    give with that.
    Also take a look at this link:
    http://www.theeldergeek.com/delete_undeletable_file.htm
     
  9. 2004/01/10
    Johanna

    Johanna Inactive Alumni

    Joined:
    2003/03/08
    Messages:
    2,402
    Likes Received:
    2
  10. 2004/01/11
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    indmusic touched on a good point. Was the download complete? And is it still in any list within kazaa? Make sure it's removed from the traffic window, delete it from the kazaa playlist, close kazaa then close it from the tray and you should be able to delete it from the folder also.
     
  11. 2004/01/13
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
    Gee Newt fill us in :)
     
  12. 2004/01/13
    goddez1

    goddez1 Inactive

    Joined:
    2002/01/12
    Messages:
    2,975
    Likes Received:
    49
    Last edited: 2004/01/13
  13. 2004/01/13
    Newt

    Newt Inactive Thread Starter

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Thanks all. I had forgotten about this thread but some excellent info in it and hopefully the fella with the problem has followed along. I did send him the link.

    I'll get with him for an update and post it here.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.