Help - Search - Members - Calendar
Full Version: HijackThis and Ad-aware will not work!
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
uncswoosh
I read all of your instructions about what to do before i post, but none of the programs will run on my computer...They all get closed before anything happens...any suggestions? I also cannot open task manager, regedit, or msconfig. Thanks.
LoPhatPhuud
You probably have the CWS Smart Killer infections which will block the major spyware removal programs from running.

Please download this file:
http://www.safer-networking.org/files/delcwssk.zip

Unzip the file and run the enclosed program.

Then run CWS Shredder, AdAware and finally, HiJackThis and post your log in the thread.
uncswoosh
I tried that utility, but it said I do not have that virus on my system...I booted in safe mode and ran HiJack This! and here is the log file, if it helps:

Logfile of HijackThis v1.97.7
Scan saved at 8:38:32 AM, on 4/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://messenger.msn.com/Help/Upgrades.aspx
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1BAC7739-A8A0-3FAE-A39A-F6B85450EFBB} - C:\WINDOWS\system32\sezmxgsm.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Ad-Aware-6] WINDOWSUPDATER.EXE
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\bxjvpgee.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\RunOnce: [Ad-Aware-6] WINDOWSUPDATER.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab

Thanks!
uncswoosh
Here is my hijack log...i cannot rud ad-aware or taskmanager or msconfig. This log was attained in safe mode, since i could not run hijack in normal mode.

Logfile of HijackThis v1.97.7
Scan saved at 8:38:32 AM, on 4/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://messenger.msn.com/Help/Upgrades.aspx
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1BAC7739-A8A0-3FAE-A39A-F6B85450EFBB} - C:\WINDOWS\system32\sezmxgsm.dll (file missing)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [Ad-Aware-6] WINDOWSUPDATER.EXE
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\bxjvpgee.exe
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\RunOnce: [Ad-Aware-6] WINDOWSUPDATER.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
FatsGordon
Hi uncswoosh!

Have you tried with the Ad-aware Cloak? You can download it from here: http://www.lavasoftnews.com/downloads/AAWCloak.exe. Once downloaded place it in a folder or the Desktop and run it BEFORE running Ad-aware, and press Activate Cloak. Then open Ad-aware, ensure yourself to have Build 6.181 and last reference file (if not please update), and perform a FULL scan as indicated in http://www.lavahelp.com/howto/fullscan/index.html. Once finished the scan and closed Ad-aware, close the Cloak.

Please post back to know whether if you succeeded or not.
uncswoosh
Thanks for the advice, but like everything else i've tried...it didnt work...any other suggestions? P.s. - i ran ad-aware in safe mode and it came up with nothing.
FatsGordon
Ok, let me analyze that HT log.

Please go to the Submission System in my signature. Copy the following files to a folder in, say, your desktop, and once copied zip them all in an only zip file. Submit that file with a brief description and also you can place 'As per FatsGordon request':

C:\WINDOWS\system32\sezmxgsm.dll (Most probably this file is not in your machine anymore)
C:\WINDOWS\System32\bxjvpgee.exe

Also try to find this file and add it to the ZIP file:

WINDOWSUPDATER.EXE

Once zipped, please close all open programs and browser windows, run HT again, press Scan and then place a checkmark to the side of the following entries (JUST THESE ENTRIES!):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://messenger.msn.com/Help/Upgrades.aspx
O2 - BHO: (no name) - {1BAC7739-A8A0-3FAE-A39A-F6B85450EFBB} - C:\WINDOWS\system32\sezmxgsm.dll (file missing)
O4 - HKLM\..\Run: [Ad-Aware-6] WINDOWSUPDATER.EXE
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\bxjvpgee.exe
O4 - HKCU\..\RunOnce: [Ad-Aware-6] WINDOWSUPDATER.EXE


This will leave an about:blank home page, but I prefer that and you can restore your home page at a later time. Press Fix checked. Then close HT.

Reboot and perform a new HT scan. Please post the new log.
FatsGordon
Sorry, I've omitted the Fix checked thing, read the above post.

You can submit that Zipped file at a later time, but once submitted please get rid of that folder.

Also: once fixed and rebooted, go to C:\WINDOWS\System32\ and locate bxjvpgee.exe. Eliminate it. The same with that WINDOWSUPDATER.EXE.

HTH :thumb:
uncswoosh
That seemed to have fixed it. Thank You very much for your assistance. I zipped and submitted the files you asked for and deleted them. Here is my new HiJack log:


Logfile of HijackThis v1.97.7
Scan saved at 6:08:09 PM, on 4/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\hijack\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\SpyHunter\SpyHunter.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0309.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033...all/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab
FatsGordon
You can still fix this:

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

And if this is NOT your ISP, you can fix this one as well:

O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com

Remember to fix them with all other programs and browser windows closed.

After that please reboot. If you want you can post another fresh HT log just to verify that all is Ok.
LoPhatPhuud
First:
Please go here and do an AV scan at one (preferably two) of the following:
Panda's Active Scan
http://www.pandasoftware.com/activescan/co...n_principal.htm

Trend Micro (PC-cillin) - Free on-line Scan
http://housecall.antivirus.com

RAV Antivirus Online Scan
http://www.ravantivirus.com/scan/

eTrust AV web scanner (Computer Associates)
http://www3.ca.com/virusinfo/virusscan.aspx


Second:
I strongly advise you to get rid of SpyHunter. In addition to producing loads of False Positives, it won't detect much of anything at all, and I believe it will charge you $29.95 if you actually want to have it remove what it found...
Uninstall it through Add/Remove Programs!
Both Ad-Aware and SpyBot S&D do an incomparably better job, and they're freeware!


Third:
Reboot in Safe Mode* and run HiJackThis.

Check the following items in HijackThis.
O2 - BHO: (no name) - {1BAC7739-A8A0-3FAE-A39A-F6B85450EFBB} - C:\WINDOWS\system32\sezmxgsm.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O4 - HKLM\..\Run: [Ad-Aware-6] WINDOWSUPDATER.EXE
O4 - HKLM\..\Run: [nvid] C:\WINDOWS\System32\bxjvpgee.exe
O4 - HKCU\..\RunOnce: [Ad-Aware-6] WINDOWSUPDATER.EXE


Close all windows except HijackThis and click Fix checked:

Reboot in Safe Mode* and delete the following: (you may need to show hidden files**)
WINDOWSUPDATER.EXE (either c:\windows\ or c:\windows\system32\)
C:\WINDOWS\System32\bxjvpgee.exe


*How to Boot into Safe mode: http://service1.symantec.com/SUPPORT/tsgen...001052409420406
**Show hidden files/folders as per the instructions here http://www.tacktech.com/display.cfm?ttid=190

Also, uncheck the boxes for hiding known file extensions and hiding protected operating system files. We want to see it all. When we finish here, it would be a good idea to rehide the protected operating system files but leave the rest to be shown.

Reboot.

Post another HiJackThis log in this thread for review.
FatsGordon
Threads merged to keep continuity.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.