Greetings,
Before you post in this forum,please read and follow the instructions in this post: Guidelines for Posting in This Forum
Failure to follow these instructions will only result in delays of the cleaning and removal process.
If you ran other AntiVirus and/or AntiSpyware programs and have the logs available, please post them as well.
Our goal is to help you clean your PC and restore it to pre-infection condition wherever possible.
Thank You
![]() ![]() |
| Guest_BLuMo0N_* |
Dec 22 2005, 05:29 PM
Post
#1
|
|
Guests |
I think i got infected or something. Cause I'm getting random pop-ups everytime I open IE which never happen before. Any Help would be appreciated.
Logfile of HijackThis v1.99.1 Scan saved at 12:17:00 PM, on 12/22/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Analog Devices\SoundMAX\Smtray.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Anti-Spyware Softwares\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\iPod\iTunes\iTunesHelper.exe c:\progra~1\intern~1\iexplore.exe C:\Program Files\Anti-Spyware Softwares\Microsoft AntiSpyware\gcasDtServ.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\mIRC\mirc.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Documents and Settings\Chris\Desktop\New Folder\Spyware Programs\Spyware Log\HijackThis v1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/chsi.html O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Anti-Spyware Softwares\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iPod\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [tonsrefprocbone] C:\Documents and Settings\All Users\Application Data\Warn About Tons Ref\Axislong.exe O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [Error way] C:\DOCUME~1\Chris\APPLIC~1\EXITTY~1\Wmasign.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1121977040171 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1124572190796 O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe |
|
|
|
Dec 23 2005, 01:50 AM
Post
#2
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15207 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
You have two LOP infections!
Reboot in Safe Mode* and run HiJackThis. <-- IMPORTANT Check the following items in HijackThis. (note: If any R* items do not appear in Safe Mode, re-run HiJackThis in Normal Mode and remove them after you finish removing these items.) O4 - HKLM\..\Run: [tonsrefprocbone] C:\Documents and Settings\All Users\Application Data\Warn About Tons Ref\Axislong.exe O4 - HKCU\..\Run: [Error way] C:\DOCUME~1\Chris\APPLIC~1\EXITTY~1\Wmasign.exe Close all windows except HijackThis and click Fix checked. While still in Safe Mode*, delete the following: (you may need to show hidden files**) (Files specified without a full path will be located in C:\Windows\ or C:\Windows\System32\) C:\Documents and Settings\All Users\Application Data\Warn About Tons Ref\ <--delete entire folder C:\DOCUME~1\Chris\APPLIC~1\EXITTY~1\ <--delete entire folder *How to Boot into Safe mode: http://service1.symantec.com/SUPPORT/tsgen...001052409420406 **Show Hidden and System files and folders: http://www.xtra.co.nz/help/0,,4155-1916458,00.html Also, uncheck the boxes for hiding known file extensions and hiding protected operating system files. We want to see it all. When we finish here, it would be a good idea to rehide the protected operating system files but leave the rest to be shown. Reboot in normal mode Run HiJackThis again and post a new log in this thread. -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
| Guest_BLuMo0N_* |
Dec 23 2005, 07:11 AM
Post
#3
|
|
Guests |
LoPhatPhuud, thanks for helping me. This is the new log that I got after you told me what to remove. By the way, what does the R* mean in your post mean? I'm noobish sorry.
QUOTE "(note: If any R* items do not appear in Safe Mode, re-run HiJackThis in Normal Mode and remove them after you finish removing these items.)" Logfile of HijackThis v1.99.1 Scan saved at 2:05:26 AM, on 12/23/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Analog Devices\SoundMAX\Smtray.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\Program Files\Winamp\winampa.exe C:\Program Files\Anti-Spyware Softwares\Microsoft AntiSpyware\gcasServ.exe C:\Program Files\iPod\iTunes\iTunesHelper.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\Anti-Spyware Softwares\Microsoft AntiSpyware\gcasDtServ.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Chris\Desktop\New Folder\Spyware Programs\Spyware Log\HijackThis v1.99.1.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://comcast.net/chsi.html O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Anti-Spyware Softwares\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iPod\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1121977040171 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1124572190796 O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe |
|
|
|
Dec 23 2005, 07:24 AM
Post
#4
|
|
![]() Master of Disaster Recovery Group: General Admin Posts: 15207 Joined: 24-March 03 From: Albuquerque, NM Member No.: 2879 |
That looks good and clean
The R* notation refers to R0, R1, R2, R3 entries in your HiJackThis log. Just a shorthand way of referring to all three. At last, your system is clean and free of spyware! Want to keep it that way? Here are some simple steps you can take to reduce the chance of infection in the future. 1. Visit Windows Update: Make sure that you have all the Critical Updates recommended for your operating system and Internet Explorer. This includes SP1 and SP2 if you use Windows XP. The first defense against infection is a properly patched Operating System. a. Windows Update: http://windowsupdate.microsoft.com/ If you have Word, Excel, Outlook or other Office programs installed. Consider using Microsoft Update instead of Windows Update. See the FAQ page here for more information: http://update.microsoft.com/microsoftupdat...t.aspx?ln=en-us Also, download and install Microsoft Baseline Analyzer.(Note that MBSA is only for Win 2000 SP3 or later and Office XP or later) When run, it will check system for security exposures, including missing updates. I suggest running it weekly. You can obtain more information here: http://www.microsoft.com/technet/security/...s/mbsahome.mspx 2. Adjust your security settings for ActiveX: Select Internet Options from the Control Panels, or from Internet Explorer (Tools -> Internet Options) Press 'default level', then OK Now press "Custom Level." In the ActiveX controls and plug-ins section set these options: 'Download signed ActiveX controls' - Prompt 'Download unsigned ActiveX controls' - Disable 'Initialize and script ActiveX controls not maked as safe'- Disable All other options accept the default For Windows XP2 SP2 users, check this link for additional steps you can take to secure Internet Explorer: http://www.microsoft.com/technet/security/...xp/iesecxp.mspx Also,for Sp2 SP2 and IE users, in IE, Tools -> Manage Add-ons will give you a list of all BHO's, Extensions, and ActiveX modules installed on your computer. You can update, enable or disable them. 3. Download and install the following free programs a. SpywareBlaster: http://www.javacoolsoftware.com/spywareblaster.html b. IE/Spyad: https://netfiles.uiuc.edu/ehowes/www/resource.htm c. BHODemon: http://www.definitivesolutions.com/bhodemon.htm 4. Install Spyware Detection and Removal Programs: You may also want to consider installing one (or more) of the following: a. Microsoft AntiSpyware: http://www.microsoft.com/athome/security/s...re/default.mspx NOTE: MS AntiSpyware only runs on Windows 2000, XP, and 2003. b. Spybot S&D: http://security.kolla.de/index.php?lang=en&page=download c. AdAware Personal: http://www.lavasoft.de/ Use these programs to regularly scan your system for and remove many forms of spyware/malware. I recommend a combination of Microsoft Spyware and TeaTimer from Spybot S&D. If you use, or plan on using, additional spyware/malware detection and/or removal programs, please check Items 8 and 9. 5. Install 'Spoofstick" Spoofstick is a simple browser extension that helps users detect spoofed (fake) websites. This extension is free and installs in Internet Explorer and Mozilla Firefox. a. http://www.corestreet.com/spoofstick 6. Reset System Restore If you are using Windows ME or Windows XP, please reset your System Restore. See Windows help for information. 7. Clean Temporary Files and Folders Download and install the disk cleanup utility called Cleanup! from here: http://cleanup.stevengould.org/ http://www.hijackthislogs.com/dl/CleanUp312.exe Cleanup! will get rid of any malware which may be hiding in your temp folders (a common hiding place). You may also regain a massive amount of disk space. Here is a tutorial which describes its usage: http://www.bleepingcomputer.com/forums/tutorial93.html Run the disk cleanup utility called Cleanup! that you have already downloaded and installed Check the custom settings to your liking under options, but be sure to delete temporary files and temporary internet files for all user profiles. Also, cleanout the prefetch folder and the recycle bin. Then reboot into normal mode to let it clean out the remaining files. 8. Rogue/Suspect Anti-Spyware Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List. It will save you a lot of grief, as well as money if you are thinking of purchasing. Here is the link: http://www.spywarewarrior.com/rogue_anti-spyware.htm 9. Anti-Spyware Programs Compared Want to know just how effective your anti-spyware program is? Wonder how well any of the "rogue" programs listed above work? Check this link for an independent comparison of several anti-spyware programs: http://www.spywarewarrior.com/asw-test-guide.htm 10. Alternate Browser Consider using an alternate browser as your default. I recommend and use Firefox as my primary browser. It is still necessary to keep Internet Explorer current and protected in order to use Windows Update. For more information about Spyware, the tools available, and other informative material, including information on how you may have been infected in the first place, please check out this link: http://forum.gladiator-antivirus.com/index...?showtopic=9857 "It is your responsibility to read and adhere to the End User Licensing Agreement (EULA) of all software and services mentioned." Good luck, and thanks for coming to our forums for help with your security and malware issues. -------------------- Happiness ain't a thing in itself--it's only a contrast with something that ain't pleasant. Mark Twain |
|
|
|
| Guest_BLuMo0N_* |
Dec 23 2005, 04:59 PM
Post
#5
|
|
Guests |
LoPhatPhuud, Thanks for help. :yahoo:
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 01:19 PM |