RSS Forums RSS
Please support our Viruses, Spyware and other Nasties advertiser: 64-bit Windows Community

hacktool.rootkit / backdoor.generic2.ppu issue

Join Date: Jul 2005
Location: FL.
Posts: 1,536
Reputation: tayspen is on a distinguished road 
Rep Power: 7
Solved Threads: 98
Colleague
tayspen's Avatar
tayspen tayspen is offline Offline
<Insert title here>

Re: hacktool.rootkit / backdoor.generic2.ppu issue

  #2  
Apr 19th, 2006
HI, please run HJT again and select Do system scan only.

Then check these items.


O2 - BHO: BandIE Class - {77FEF28E-EB96-44FF-B511-3185DEA48697} - C:\PROGRA~1\baidu\bar\baidubar.dll

O2 - BHO: IE - {D157330A-9EF3-49F8-9A67-4141AC41ADD4} - C:\WINDOWS\downlo~1\CnsHook.dll

O3 - Toolbar: 百度超级�霸 - {B580CF65-E151-49C3-B73F-70B13FCA8E86} - C:\PROGRA~1\baidu\bar\baidubar.dll

O4 - HKLM\..\Run: [CnsMin] Rundll32.exe C:\WINDOWS\downlo~1\CnsMin.dll,Rundll32

O4 - HKLM\..\Run: [stup.exe] C:\PROGRA~1\TENCENT\Adplus\stup.exe

O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe

O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm

O8 - Extra context menu item: 添加到QQ自定义�� - C:\Program Files\Tencent\QQ\AddPanel.htm

O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm

O8 - Extra context menu item: 用QQ彩信��该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm

O8 - Extra context menu item: 用比特精�下载(&B) - C:\Program Files\BitSpirit\bsurl.htm

O18 - Protocol: koboo - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll

O18 - Protocol: mbox - {7DEE9D05-FA0A-4416-A6F3-6537D0EAB6A6} - C:\WINDOWS\system32\mbprot.dll

O18 - Filter: text/html - {83DFBFF3-1455-4538-8036-39D2057787DF} - C:\WINDOWS\gsSecurity1.dll



Then click Fix Checked

---------------------------------------------------------------

Download pocket killbox from http://www.thespykiller.co.uk/files/killbox.exe & put it on the desktop where you can find it easily

Now Start killbox Copy the list of files below to the clipboard by selecting all of them with your mouse (Left click the start of the list and drag the mouse to the bottom of the list) and when they are all selected ( highlighted in blue) right click on any part of the blue area and say copy

In the Killbox, Go to the toolbar press file and select Paste from clipboard. The first file name will appear in the window and if the file exists it will appear in blue under that window then select standard file kill, press the red X button, say yes to the prompt and once the file deleted message comes up then press the red X again and continue to press untill the last file on the list appears in the window & it says deleted.

File list:

C:\Program Files\Tencent\QQ\QQ.exe

C:\Program Files\Tencent\QQ\AddToNetDisk.htm

C:\Program Files\Tencent\QQ\AddPanel.htm

C:\Program Files\Tencent\QQ\AddEmotion.htm

C:\Program Files\Tencent\QQ\SendMMS.htm

C:\Program Files\BitSpirit\bsurl.htm

C:\WINDOWS\system32\mbprot.dll

C:\WINDOWS\gsSecurity1.dll

If any give you an deletion error, just take not of which it was then skip it...

Then please delete the folloqing folder.

C:\Program Files\Tencent\QQ\

Then empty recycle bin

-------------------------------------------------------
Then download ewido (www.ewido.net). Install. Update. Scan. (Save the log).

Post a new HJT log, and ewido log
Firefox
Ewido
Tune up windows
Get detailed system information
My Fixes

Member - Alliance of Security Analysis Professionals - Since 2006
Reply With Quote  
Forums | Blogs | Tutorials | Code Snippets | Whitepapers | RSS Feeds | Advertising
All times are GMT -4. The time now is 3:21 am.
Newsletter Archive - Sitemap - Privacy Statement - Acceptable Use Policy - Contact Us
Forum system based on vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
©2003 - 2008 DaniWeb® LLC