Help!

Weird Thingy In The Log Worrying Me, Plus Recent Pop-ups.

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs RSS
Next:  Winlogon.exe Error Please Help!  
Author Message
nosnaj



Joined: Mar 02, 2006
Posts: 3



PostPosted: Thu Mar 02, 2006 3:13 am    Post subject:

NOTE: Windows1 is my root directory and !Xobile is just a name.
NOTE: I keep getting pop-ups that has different URLs, and all redirects to match.com. for example "http://www.intern-etadvertising.com/normal/yyy102.html","http://www.hug-ediscounts.com/normal/yyy102.html" though sometimes I get some others too.(diff from yyy102.html)
And I get flash ads that pop out from nowhere. (diff from yyy102.html)




[I'll include more screenshots of them if they are needed.]

Logfile of HijackThis v1.99.1
Scan saved at 21:51:01, on 2/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\System32\svchost.exe
C:\WINDOWS1\system32\spoolsv.exe
C:\WINDOWS1\Explorer.EXE
C:\WINDOWS1\System32\lssas.exe
C:\WINDOWS1\System32\ctfmon.exe
C:\WINDOWS1\System32\nvsvc32.exe
C:\WINDOWS1\wscntify.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS1\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\!Xobile\Desktop\Mixed Software\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS1\System32\msdxm.ocx
O4 - HKLM\..\Run: [AdobeReaderPro] lssas.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS1\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\RunServices: [AdobeReaderPro] lssas.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS1\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF55B262-66E2-4650-A98B-55012DF14ED9}: NameServer = 202.188.0.133 202.188.1.5
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS1\system32\ktn6l75s1.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS1\System32\nvsvc32.exe
O23 - Service: security centre (windows security centre) - Unknown owner - C:\WINDOWS1\wscntify.exe




Help is much appreciated! Though I don't know how to repay, sorry.
And I hope that I have provided ample information.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Thu Mar 02, 2006 4:30 pm    Post subject:

Welcome to Lockergnome.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Please download Ewido Security Suite at http://www.ewido.net/en/download/.

1. Install Ewido Security Suite.
2. When installing, under 'Additional Options' uncheck:
* Install background guard
* Install scan via context menu
3. Launch Ewido, there should be an icon on your desktop, double click it.
4. The program will now open to the main screen.
5. When you run Ewido for the first time, you will get a warning 'Database could not be found!'. Click OK. We will fix this in a moment.
6. You will need to update Ewido to the latest definition files.
* On the left hand side of the main screen click update.
* Then click on Start Update.
7. The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display 'Update successful'.
8. Exit Ewido. DO NOT scan yet.

If you are having problems with the updater, you can go to http://www.ewido.net/en/download/updates/ to update manually.

Download CleanUp! http://cleanup.stevengould.org/ (Alternate Link if main link don't work - http://www.greyknight17.com/spy/CleanUp.exe ) and install it. Don't run it yet.

Download CWShredder at http://www.greyknight17.com/spy/CWShredder.exe and run it. Click on 'I Agree' button if you agree. Click on 'Fix' (it will automatically fix anything it finds for you) and then click OK. If it asks if you want to delete a certain random file, choose No and post that filename here. Let it finish the scan and then hit Next and Exit.

Restart your computer and boot into Safe Mode (if you don't know how, go to http://www.bleepingcomputer.com/forums/ind...showtutorial=61 ).

CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these before running CleanUp!. Run CleanUp! and click on the Options button. Uncheck 'Scan local drives for temporary files'. Also uncheck those two Newsgroup entries if you don't want to delete them. Click OK and then click on the CleanUp! button. Let it run. After it's done, choose Yes to logoff.

Now open Ewido and do a scan on your system.

* Click on scanner.
* Click on 'Complete System Scan' and the scan will begin.
* While the scan is in progress you will be prompted to clean the first infected file it finds. Choose 'Remove', then put a check next to 'Perform action on all infections' in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.
Exit Ewido when it's done.
* Once the scan has completed, there will be a button located on the bottom of the screen named 'Save report'.
* Click 'Save report'.
* Save the report to your desktop.

Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you check the last one:

O4 - HKLM\..\Run: [AdobeReaderPro] lssas.exe
O4 - HKLM\..\RunServices: [AdobeReaderPro] lssas.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS1\web\related.htm
O20 - Winlogon Notify: Syncmgr - C:\WINDOWS1\system32\ktn6l75s1.dll


Locate and delete the following:

lssas.exe - make SURE it's spelled exactly as shown here

Restart your computer to get back to Normal Mode.

Download L2MFix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts. Then open the newly added l2mfix folder on your desktop.

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing Enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2MFix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new HijackThis log and the Ewido report.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

Also go to the Windows Update site now and make sure you got all the critical and recommended updates installed.
Back to top
AIM Address Yahoo Messenger
nosnaj



Joined: Mar 02, 2006
Posts: 3



PostPosted: Fri Mar 03, 2006 2:14 am    Post subject:

L2mfix 010406
Creating Account.
The command completed successfully.

Adding Administrative privleges.
The command completed successfully.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX ... successful
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
zip warning: name not matched: dlls\*.*

zip error: Nothing to do! (backup.zip)
adding: backregs/notibac.reg (164 bytes security) (deflated 87%)

---------------

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 14:47:05, 3/3/2006
+ Report-Checksum: 15E4A7EE

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{6001CDF7-6F45-471b-A203-0225615E35A7} -> Adware.Generic : Cleaned with backup
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup
HKU\S-1-5-18\Software\Effective-i -> Adware.EffectiveBrandToolbar : Cleaned with backup
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Cleaned with backup
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Cleaned with backup
[1468] C:\WINDOWS1\system32\cuvfat.dll -> Adware.Look2Me : Cleaned with backup
C:\dr.exe -> Downloader.VB.ws : Cleaned with backup
C:\drmt32.exe -> Downloader.Adload.t : Cleaned with backup
C:\drsmart32.exe -> Downloader.Adload.t : Cleaned with backup
C:\gimmygames12.exe -> Downloader.Adload.v : Cleaned with backup
C:\gotya.exe -> Downloader.Adload.q : Cleaned with backup
C:\Installer.exe -> Adware.Look2Me : Cleaned with backup
C:\MTE3NDI6ODoxNg.exe -> Downloader.Small.buy : Cleaned with backup
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\ucmoreiex.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup
C:\ucmoreiex.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup
C:\WINDOWS1\DH.dll -> Hijacker.Small.jf : Cleaned with backup
C:\WINDOWS1\icont.exe -> Adware.AdURL : Cleaned with backup
C:\WINDOWS1\iconu.exe -> Adware.Zestyfind : Cleaned with backup
C:\WINDOWS1\iexpress.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS1\Q2hhbg\asappsrv.dll -> Adware.CommAd : Cleaned with backup
C:\WINDOWS1\Q2hhbg\command.exe -> Adware.CommAd : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\E85THPJ9\MTE3NDI6ODoxNg[1].exe -> Downloader.Small.buy : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\NZ3YDRX5\winsysban12[1].exe -> Hijacker.VB.li : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Q25003JE\Installer[1].exe -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Q25003JE\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Q25003JE\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\Q25003JE\winsysupd12[1].exe -> Hijacker.StartPage.aib : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\VHFH36QF\dr[1].exe -> Downloader.VB.ws : Cleaned with backup
C:\WINDOWS1\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\VHFH36QF\gimmygames12[1].exe -> Downloader.Adload.v : Cleaned with backup
C:\WINDOWS1\system32\cuvfat.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\guard.tmp -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\iyxmontr.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\logon.exe -> Dropper.Paradrop.a : Cleaned with backup
C:\WINDOWS1\system32\lssas.exe -> Backdoor.Rbot.arr : Cleaned with backup
C:\WINDOWS1\system32\mkimg32.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\muhcp.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\mzir3jp.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\plchdprf.dll -> Adware.Look2Me : Cleaned with backup
C:\WINDOWS1\system32\svxhost.exe -> Backdoor.Rbot : Cleaned with backup
C:\WINDOWS1\wscntify.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\winsysban12.exe -> Hijacker.VB.li : Cleaned with backup
C:\winsysupd12.exe -> Hijacker.StartPage.aib : Cleaned with backup


::Report End

----------------

Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS1\System32\smss.exe
C:\WINDOWS1\system32\winlogon.exe
C:\WINDOWS1\system32\services.exe
C:\WINDOWS1\system32\lsass.exe
C:\WINDOWS1\system32\svchost.exe
C:\WINDOWS1\Explorer.EXE
C:\WINDOWS1\system32\spoolsv.exe
C:\WINDOWS1\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS1\System32\nvsvc32.exe
C:\WINDOWS1\win32ssr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\!Xobile\Desktop\Mixed Software\HijackThis.exe

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS1\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS1\System32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS1\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{BF55B262-66E2-4650-A98B-55012DF14ED9}: NameServer = 202.188.0.133 202.188.1.5
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS1\system32\ktp2l77o1.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS1\System32\nvsvc32.exe
O23 - Service: Performance True Type Font (PerfFont) - Unknown owner - C:\WINDOWS1\System32\perfont.exe
O23 - Service: Win32Sr - Unknown owner - C:\WINDOWS1\win32ssr.exe
O23 - Service: security centre (windows security centre) - Unknown owner - C:\WINDOWS1\wscntify.exe (file missing)

-------------------

I actually see that more random exes has appeared in the hjt log...
the CWShredder didnt detect anything.
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Fri Mar 03, 2006 4:28 pm    Post subject:

Print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below.

Run a scan in HijackThis. Check each of the following if they still exist and hit 'Fix Checked' after you check the last one:

O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS1\system32\ktp2l77o1.dll (file missing)
O23 - Service: Performance True Type Font (PerfFont) - Unknown owner - C:\WINDOWS1\System32\perfont.exe
O23 - Service: Win32Sr - Unknown owner - C:\WINDOWS1\win32ssr.exe
O23 - Service: security centre (windows security centre) - Unknown owner - C:\WINDOWS1\wscntify.exe (file missing)


Go to Start->Run and type in notepad and hit OK. Then copy and paste the following into Notepad:

sc stop "windows security centre"
sc delete "windows security centre"
del delete.bat


Save the file as "delete.bat". Make sure to save it with the quotes. Double click on it.


Locate the following Files/Folders and delete them if they exist (if no location given, just do a search for them):

C:\WINDOWS1\System32\perfont.exe
C:\WINDOWS1\win32ssr.exe


Restart. Try this again:

Download L2MFix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts. Then open the newly added l2mfix folder on your desktop.

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing Enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2MFix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and post it here.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

Perform an online scan with Internet Explorer at Panda ActiveScan http://www.pandasoftware.com/products/activescan.htm

* Click on 'Scan your PC' button. There should be a popup - if you have a pop-up blocker, make sure it's not blocking it.
* Click 'Check Now' & a pop-up window will appear.
* Enter your Country, State and E-mail Address & click 'Scan Now' - begin downloading Panda's ActiveX controls (8 MB size).
* Begin the scan by selecting My Computer.
* If it finds any malware, it will offer you a report. Ignore any entry it finds (since it wants you to buy the program for removal) as we will address this later.
* Click on see report. Then click Save report.
* Post that log in your next reply along with a new HijackThis log.
Back to top
AIM Address Yahoo Messenger
nosnaj



Joined: Mar 02, 2006
Posts: 3



PostPosted: Fri Mar 03, 2006 6:29 pm    Post subject:

Do I do the first few steps in Safe Mode?
Back to top
greyknight17



Joined: Feb 03, 2003
Posts: 5674

Location: Brooklyn, NY

PostPosted: Sat Mar 04, 2006 6:32 pm    Post subject:

You may....

Any updates on this since we spoke yesterday on IM? :laugh:
Back to top
AIM Address Yahoo Messenger
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> HijackThis Logs All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum