Help - Search - Members
Full Version: Please help me with my HJT log
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
KindredWarr
I've ran all the programs in the Spyware Removal guide except for Spybot Search & Destroy.
For whatever reason SS&D takes all day long to do it's thing, I don't remember it doing that before.. but for some reason it seriously takes all day long to do.

My biggest problem is my google searches getting hijacked in I.E. I'll be taken to different places, mainly ebay searches or some crappy casino site. I've ran Ad-Aware a million or so times and keep checking my computer with Trend-Micro's virus search (which gives me an odd error when I try and use them now..) and can't seem to get rid of it. So any help would be great.

Thank you

QUOTE
Logfile of HijackThis v1.99.1
Scan saved at 6:10:29 PM, on 1/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Media Connect 2\WMCCFG.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HIjack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lasvegas.cox.net/cci/home
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.0.69.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: MD Simple Burner Service (NetMDSB) - Sony Corporation - C:\Program Files\Sony\MD Simple Burner\NetMDSB.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe
AndyManchesta
Hi KindredWarr biggrin.gif

Thats a clean log, The only thing that stands out is the lack of Antivirus or Firewall programs, Here's a couple of free programs if you need them :

Antivirus :

eTrust EZ Antivirus - 12 Month Trial Version for all Microsoft customers

AVG free edition

AntiVir PersonalEdition Classic

Firewall:

Outpost Firewall Free

Sygate Personal Firewall

ZoneAlarm Free


EZ Antivirus and Zonealarm are what I use on my machines and they perform great and provide excellent protection,

Regarding your redirections it may be worth running an alternative Antivirus scanner and checking your hosts file, It should show hosts file entries in the Hijack This log but to be safe its worth us making sure its not been modified without your consent.

Run a full system scan with Panda's Activescan. Select MyComputer so it performs a full scan and Save the scan log when its finished and post that back if it finds problems.

Panda Activescan


Next Download Toadbee's Hoster from HERE

Run Hoster, If you use protection software that modifies your hosts file such as MVPS Hosts then choose the Copy to Clipboard option on Hoster so you can post the contents back here, the default Hosts file should look like this:

# Copyright © 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a "#" symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host
#
127.0.0.1 localhost


If you have extra entries below the 127.0.0.1 localhost line post back the contents so we can check for any malicious lines, Alternatively you can reset the Hosts file to Microsoft's default (As Above) by simply pressing 'Restore Original Hosts' using Hoster.

Let us know if the problems continue,

Regards

Andy
KindredWarr
Hi,
Thank you for your help, I installed EZ Antivirus and ran it, removed a trojan I had here, but nothing else.

I haven't gotten around to install a firewall, but soon, I'm doing my best to keep a bunch of things from running at once since my PC is mainly used for gaming, and firewalls always mucked up connections for online gaming, at least for me, either that or my router did it.. er, anyways..

I ran panda activescan and came back with this log.


QUOTE
Incident Status Location

Adware:adware/ideskbar Not disinfected C:\WINDOWS\SYSTEM32\idesk.conf
Adware:adware/sbsoft Not disinfected C:\WINDOWS\rdt.ini
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\warren lamb\Cookies\warren lamb@com[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\warren lamb\Cookies\warren lamb@realmedia[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\warren lamb\Cookies\warren lamb@com[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\warren lamb\Cookies\warren lamb@realmedia[1].txt
Hacktool:HackTool/EvID Not disinfected C:\EventID\EvID4226Patch.exe



after I ran that I ran the ez antivirus scanner, and still no luck with that piece of crap hijacker. I did a little research and found that most of my searches get redirected to the following IP: 85.255.115.162 even more searching lead me to another post on another site where some one was having similar problems, however the suggestions there didn't seem to really work for me, but I did find a usefull little program called blacklight that shows me a bunch of hidden processes, searching a few of them, it looks like they may be the cause of all my troubles, but I find it a little weird multiple scans didn't show crap on 'em.. so maybe they're not the cause? anyhow, here's the log

QUOTE
01/15/06 02:16:27 [Info]: BlackLight Engine 1.0.30 initialized
01/15/06 02:16:27 [Info]: OS: 5.1 build 2600 (Service Pack 2)
01/15/06 02:16:28 [Note]: 7019 4
01/15/06 02:16:28 [Note]: 7005 0
01/15/06 02:16:33 [Note]: 7006 0
01/15/06 02:16:34 [Note]: 7011 332
01/15/06 02:16:34 [Note]: FSRAW library version 1.7.1014
01/15/06 02:16:40 [Info]: Hidden file: C:\Program Files\HP\Digital Imaging\bin\DestTest.exe
01/15/06 02:16:40 [Note]: 10002 1
01/15/06 02:17:56 [Info]: Hidden file: C:\WINDOWS\system32\wbem\wbemtest.exe
01/15/06 02:17:56 [Note]: 10002 1
01/15/06 02:17:58 [Info]: Hidden file: C:\WINDOWS\system32\filesafer23.exe
01/15/06 02:17:58 [Note]: 10002 1
01/15/06 02:18:00 [Info]: Hidden file: C:\WINDOWS\system32\dmwnt.exe
01/15/06 02:18:00 [Note]: 7002 32
01/15/06 02:18:00 [Note]: 7003 1
01/15/06 02:18:00 [Note]: 10002 1
01/15/06 02:18:01 [Info]: Hidden file: C:\WINDOWS\system32\howiper.exe
01/15/06 02:18:01 [Note]: 10002 1
01/15/06 02:18:03 [Info]: Hidden file: C:\WINDOWS\system32\pppcgm.exe
01/15/06 02:18:03 [Note]: 10002 1
01/15/06 02:18:07 [Info]: Hidden file: C:\WINDOWS\system32\cstcm.exe
01/15/06 02:18:07 [Note]: 7002 32
01/15/06 02:18:07 [Note]: 7003 1
01/15/06 02:18:07 [Note]: 10002 1
01/15/06 02:18:10 [Info]: Hidden file: C:\WINDOWS\system32\sphlp32.exe
01/15/06 02:18:10 [Note]: 10002 1
01/15/06 02:18:34 [Note]: 7007 0



Once again, ANY help would be appreciated.. or am I just totally screwed here?
crunchie
Of those files in Blacklights log, did you rename any? This one and the hp one are legit and so should not be renamed; C:\WINDOWS\system32\wbem\wbemtest.exe
Allow Blacklight to rename the rest. It will then want you to reboot your PC. Do so. You must then delete the files you had Blacklight rename, reboot, rescan with hijackthis and post another log. Hopefully a hidden file will be revealed.
KindredWarr
I don't know why I glanced over or ignored the rename thing... but it did the trick. All of it's gone and my PC is good now. biggrin.gif Thank you and you also for all the help AndyManchesta
AndyManchesta
Nice work KindredWarr

Sorry about the delay in responding, I was working long hours and only just had a chance to check my emails but many thanks to Crunchie for stepping in biggrin.gif

As Crunchie said if you have renamed the files they should now be removed from the system but you may need to enable hidden files to locate them all.

To Enable hidden files:

Click Start > Open My Computer > Select the Tools menu from the top bar and click Folder Options > Select the View Tab.

Under the Hidden files and folders heading select Show hidden files and folders.
Uncheck the Hide protected operating system files (recommended) option.

Click Yes to confirm > Click OK.

Set this back after you have checked for the files by opening the same page and pressing "Restore Defaults"

Delete these files:

C:\WINDOWS\rdt.ini
C:\WINDOWS\system32\filesafer23.exe.ren
C:\WINDOWS\system32\dmwnt.exe.ren
C:\WINDOWS\system32\pppcgm.exe.ren
C:\WINDOWS\system32\howiper.exe.ren
C:\WINDOWS\system32\cstcm.exe.ren
C:\WINDOWS\system32\sphlp32.exe.ren
C:\WINDOWS\system32\idesk.conf


Regarding the hacktool (EvID4226Patch.exe) it appears to be related to This Site so if you downloaded it yourself and know its there then its not a problem otherwise remove it.

It may also be a good idea to run Ewido on your system to check for any remaining problems that didnt show in your log,

Download, install, and update the free version of ewido security suite

http://www.ewido.net/en/download/

When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". Click on update in the left menu, then click the Start update button. After the update finishes from the main menu click on 'scanner' then click 'Complete System Scan' When ewido finds something, it will pop up a notification. Select "Remove" and check the boxes "Perform action with all infections" and "Create encrypted backup" then click on ok.When the scan finishes, click on "Save Report" and save it to your desktop or c:/drive incase you need it again.

Its good to hear you added Antivirus protection to your system as that will help reduce the chances of further infection but here's some additional programs that will not use alot of system resources as they either perform the tasks and then close or are on-demand scanners which only run when you open them :

Spyware Blaster. A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here

Ad-Aware SE.A tutorial on using Ad-Aware to remove spyware from your computer may be found here

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" feature.

Update & Run these programs regularly and your chances of being infected again will reduce dramatically.

All The Best
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.