Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
 
Old 03-11-2008, 06:08 PM   #1 (permalink)
jesspren6's Avatar
 
Super Techie

Join Date: May 2006

Posts: 266

jesspren6 is on a distinguished road

Default HJT log

I have a pc that comes with a pop up once and a while that says the pc has a worm.win32.netsky virus. When I go to the internet, my homepage gets jacked by ucleaner.com and another one, I forgot the name of the 2nd.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:57:28 PM, on 3/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Mitchell1\Manager\Series1\Series10.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\MITCHE~1\ONDEMA~1\Od5.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = UltimateCleaner 2007
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: RDL Rolex - {87F99AD1-22A9-46AD-8BCD-DEF34C065CA6} - C:\WINDOWS\drnpfdxvsl.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O21 - SSODL: bokpkov - {7A6CA83A-24FE-4101-8919-63FDEE352799} - C:\WINDOWS\bokpkov.dll
O21 - SSODL: altvxvm - {A0397EBF-B02D-4D33-A37F-65C0B3CF9C71} - C:\WINDOWS\altvxvm.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 6037 bytes
__________________
Make easy money by joining http://cashcrate.com/185982 and doing surveys. 100% free and doesn't require a credit card.
jesspren6 is offline  
Old 03-11-2008, 07:57 PM   #2 (permalink)
ECTech's Avatar
 
Neowin.net

Join Date: Jul 2005

Posts: 633

ECTech

Default Re: HJT log

If Norton is completely up to date it should remove Netsky.


remove these,

O2 - BHO: RDL Rolex - {87F99AD1-22A9-46AD-8BCD-DEF34C065CA6} - C:\WINDOWS\drnpfdxvsl.dll

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)

O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)

O21 - SSODL: bokpkov - {7A6CA83A-24FE-4101-8919-63FDEE352799} - C:\WINDOWS\bokpkov.dll

O21 - SSODL: altvxvm - {A0397EBF-B02D-4D33-A37F-65C0B3CF9C71} - C:\WINDOWS\altvxvm.dll

O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm


After, go through this guide. http://www.tech-forums.net/pc/f51/sp...osiris-165828/
ECTech is offline  
Old 03-11-2008, 08:02 PM   #3 (permalink)
jesspren6's Avatar
 
Super Techie

Join Date: May 2006

Posts: 266

jesspren6 is on a distinguished road

Default Re: HJT log

I think I tried to delete these, and HJT said it did, until I rescanned.

O21 - SSODL: bokpkov - {7A6CA83A-24FE-4101-8919-63FDEE352799} - C:\WINDOWS\bokpkov.dll

O21 - SSODL: altvxvm - {A0397EBF-B02D-4D33-A37F-65C0B3CF9C71} - C:\WINDOWS\altvxvm.dll
__________________
Make easy money by joining http://cashcrate.com/185982 and doing surveys. 100% free and doesn't require a credit card.
jesspren6 is offline  
Old 03-11-2008, 11:07 PM   #4 (permalink)
ECTech's Avatar
 
Neowin.net

Join Date: Jul 2005

Posts: 633

ECTech

Default Re: HJT log

Great, now what i'd like you to do is restart your computer into safe mode so we can remove those. That infection seems to be a fairly new one.


First, let's install Spyware Doctor. It can be found here... Google Pack

After you install it, update it and run a full system scan. Once it has finished, restart into safe mode run another scan.


How to get into Safe Mode.

1. Restart your computer.
2. When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
3. Select the option for Safe Mode using the arrow keys.
4. Then press enter on your keyboard to boot into Safe Mode.
5. Do whatever tasks you require and when you are done reboot to boot back into normal mode.

post another log when ur finished.

Last edited by ECTech; 03-11-2008 at 11:09 PM.
ECTech is offline  
Old 03-12-2008, 07:35 AM   #5 (permalink)
Redmo0n's Avatar
 
Techalicious

Join Date: Aug 2007

Location: Perth, Australia

Posts: 1,573

Redmo0n is on a distinguished road

Send a message via MSN to Redmo0n
Default Re: HJT log

Why spyware doctor :/
__________________
Back to stay?
Redmo0n is offline  
Old 03-12-2008, 08:05 AM   #6 (permalink)
ECTech's Avatar
 
Neowin.net

Join Date: Jul 2005

Posts: 633

ECTech

Default Re: HJT log

cuz spyware doctor has the largest signature database out there. it's by far one of the top malware removal programs on the market. plus not all programs will run in safe mode.
ECTech is offline  
Old 03-13-2008, 07:30 PM   #7 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,232

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: HJT log

Has this be resolved?
__________________
Osiris is offline  
Old 03-14-2008, 01:32 AM   #8 (permalink)
jesspren6's Avatar
 
Super Techie

Join Date: May 2006

Posts: 266

jesspren6 is on a distinguished road

Default Re: HJT log

Yes, sorry, I just fixed it earlier today.
__________________
Make easy money by joining http://cashcrate.com/185982 and doing surveys. 100% free and doesn't require a credit card.
jesspren6 is offline  
Old 03-14-2008, 07:48 AM   #9 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,232

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: HJT log

ok, thx
__________________
Osiris is offline  
 
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Can you help? HJT log attached... dancingslave HijackThis Logs (finished) 10 03-15-2008 11:14 AM
HJT log from a business computer cwr89 HijackThis Logs (finished) 7 02-15-2008 08:22 PM
HJT log mds303 HijackThis Logs (finished) 3 01-12-2008 01:36 PM
HJT Log. Lukey114 HijackThis Logs (finished) 20 12-20-2007 06:49 AM
HJT Log Preacher HijackThis Logs (finished) 9 12-15-2007 03:32 PM