jdrichar Posted October 9, 2004 Report Share Posted October 9, 2004 When browsing, a site (http://t.swapx.cc/h.php?aid=80) pops up frequently. Certain sites, like my e-mail, cannot even be viewed. Also, I get two porn sites added to my favorited, and no matter how many times I delete them, they always ome back. Here is my HjT log:Logfile of HijackThis v1.98.2Scan saved at 10:26:03 AM, on 10/9/2004Platform: Windows XP (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 (6.00.2600.0000)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\csrss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\System32\svchost.exeC:\WINNT\Explorer.EXEC:\WINNT\system32\spoolsv.exec:\Program Files\Norton AntiVirus\navapsvc.exeC:\WINNT\System32\igfxtray.exeC:\WINNT\System32\hkcmd.exeC:\WINNT\System32\SK9910DM.EXEC:\WINNT\GWMDMMSG.exeC:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exeC:\PROGRA~1\NORTON~1\navapw32.exeC:\Program Files\Real\RealPlayer\RealPlay.exeC:\WINNT\System32\swxkqg.exeC:\Program Files\Messenger\msmsgs.exeC:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXEC:\WINNT\System32\wuauclt.exeC:\Program Files\Juno6\qs\exec.exeC:\Program Files\Juno6\qs\exec.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Common Files\Symantec Shared\nmain.exec:\PROGRA~1\NORTON~1\navw32.exeC:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\ZMOF7DW9\hijackthis[1]\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://super-spider.com/sp.htm?id=80R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://my.juno.com/s/search?r=minisearchR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearchR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=80R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://my.juno.com/s/search?r=minisearchR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://my.juno.com/s/search?r=minisearchR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://my.juno.com/s/search?r=minisearchR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://my.juno.com/s/search?r=minisearchR1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.gateway.netR3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\JUSearch\SearchEnh1.dllF2 - REG:system.ini: UserInit=C:\WINNT\System32\Userinit.exeO2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dllO2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINNT\System32\RXLNFU~1.DLLO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocxO3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dllO3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_5.dllO4 - HKLM\..\Run: [igfxTray] C:\WINNT\System32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINNT\System32\hkcmd.exeO4 - HKLM\..\Run: [Hot Key Kbd 9910 Daemon] SK9910DM.EXEO4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exeO4 - HKLM\..\Run: [Keyboard Preload Check] C:\OEMDRVRS\KEYB\Preload.exe /DEVID: /CLASS:Keyboard /RunValue:"Keyboard Preload Check"O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"O4 - HKLM\..\Run: [NAV Agent] c:\PROGRA~1\NORTON~1\navapw32.exeO4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYERO4 - HKLM\..\Run: [gggvrepb] C:\WINNT\System32\swxkqg.exeO4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exeO4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [EPSON Stylus C40 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /P23 "EPSON Stylus C40 Series" /O6 "USB001" /M "Stylus C40"O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exeO4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"O4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dllO4 - HKCU\..\Run: [spc_w] "C:\Program Files\JUSearch\hcm.exe" -wO4 - HKCU\..\RunServices: [image] rundll32 C:\WINNT\d3wz.dll,InstallO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO4 - Global Startup: winlogin.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dllO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htmO9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htmO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dllO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: *.greg-search.comO16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\kxqwxepb.exeO16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4...006_regular.cabO16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/cha...v43/yacscom.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cabO16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CABO16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (&Yahoo! Companion) - http://us.dl1.yimg.com/download.yahoo.com/.../yiebio4025.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{BDE86981-BFC4-4A79-A9E0-C137686791F8}: NameServer = 64.136.28.120 64.136.20.120O20 - AppInit_DLLs: vz29kvl7s1zl0.dll Link to post Share on other sites
robroy Posted October 9, 2004 Report Share Posted October 9, 2004 Sounds like a hijackhave you run ad aware, spybot s & d etc.Move hijack this to its own folder away from the temporary internet folder wher it could get deletedJD Link to post Share on other sites
therock247uk Posted October 9, 2004 Report Share Posted October 9, 2004 (edited) 1. Download adaware from http://www.lavasoft.de/support/download/ install it and update it. Dont run the scan with it yet we will do that later on. 2. Ok go into safemode following instructions on http://service1.symantec.com/SUPPORT/tsgen...0010524094204063. When in safemode. Open Adaware which is what you downloaded earlyer. Before scanning with Ad-aware SE Free:Run a FULL adaware scan using the following configuration belowClick Start Select Perform Full System Scan and hit Next to let Ad-Aware scan your drives. It will list malware files and registry keys. Click Next.Under the Critical Objects tab, rightclick in the list, choose Select All, then Next.It will ask for verification of checked items. Choose OK.Close Ad-Aware, Reboot into normal mode.4. Then post a new Hijakckthis log here in a reply. Edited October 9, 2004 by therock247uk Link to post Share on other sites
therock247uk Posted October 9, 2004 Report Share Posted October 9, 2004 (edited) Ok because you cannot run both Adaware and housecall we are going to do this.1. Make sure you have show hidden files on go here for instructions. http://www.xtra.co.nz/help/0,,4155-1916458,00.html Boot into safemode if you dont know how go here for Instructions. http://service1.symantec.com/SUPPORT/tsgen...0010524094204062. While in safemode. Open Hijackthis and click scan. Then tick and fix the following in hijackthis with all windows closed except Hijackthis leaving hijackthis the only program open.R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://super-spider.com/sp.htm?id=80R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://win-eto.com/hp.htm?id=80R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blankR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O2 - BHO: (no name) - {2E9CAFF6-30C7-4208-8807-E79D4EC6F806} - C:\Program Files\Submit\submithook.dllO2 - BHO: (no name) - {467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E} - C:\WINNT\System32\RXLNFU~1.DLLO4 - HKLM\..\Run: [gggvrepb] C:\WINNT\System32\swxkqg.exeO4 - HKLM\..\Run: [WinTools] C:\Program Files\Common Files\WinTools\WToolsA.exeO4 - HKCU\..\Run: [uninstal] regsvr32 /u /s image.dllO4 - HKCU\..\RunServices: [image] rundll32 C:\WINNT\d3wz.dll,InstallO4 - Global Startup: winlogin.exeO9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind.dllO16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\kxqwxepb.exeO16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4...006_regular.cabO16 - DPF: {486E48B5-ABF2-42BB-A327-2679DF3FB822} - http://akamai.downloadv3.com/binaries/IA/ia_XP.cabO20 - AppInit_DLLs: vz29kvl7s1zl0.dll3. Go to Start, Control Panel, Add/Remove and uninstall Wintools if it is there.4. Delete the folders.C:\Program Files\Submit\C:\Program Files\Common Files\WinTools\C:\Program Files\SideFind\5. Delete the files.C:\WINNT\System32\swxkqg.exeimage.dll < Might be in C:\WINNT\ or C:\WINNT\System32vz29kvl7s1zl0.dll < Might be in C:\WINNT\ or C:\WINNT\System32C:\Program Files\Internet Explorer\kxqwxepb.exeC:\WINNT\System32\RXLNFU~1.DLL < File starts with RXLNFU6. Reboot into normal mode and post a new Hijackthis log here in a reply. Edited October 9, 2004 by therock247uk Link to post Share on other sites
Chappy Posted October 10, 2004 Report Share Posted October 10, 2004 I also noticed that neither XP nor IE have any patches applied. This is a very dangerous way to run your machine as many known vulnerabilities exist and can be exploited along with your spyware problems.Please visit MS Windows Update and apply SP2 for XP and IE.Dave Link to post Share on other sites
Recommended Posts