943,589 Members | Top Members by Rank

Ad:
You are currently viewing page 1 of this multi-page discussion thread
Nov 13th, 2007
0

Yet another with Security Toolbar infestation!

Expand Post »
Hi;
Windows XP; i've run smitfraudfix in safe mode, spydoctor with anti-virus, SuperAntiVirus, and SpyBot to no avail. i couldn't get SpyNoMore to download without hanging up and going non-responsive. I'm currently posting from another computer, i will (hopefully be able to) download Hijackthis and combofix when i get to the infected computer and will post the logs here. It's very difficult for me to get online with the infected machine because of the browser hijacker and multiple browser pages it triggers. Reinstalling the OS isn't an option. I need help on this one, would like to shoot those responsible for this! I rarely surf the web with the machine it's on, i think it came through with an Acrobat update done while trying to view a product catalog. Any help would be appreciated, i've burned up 2 days on this already!
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
73firebird is offline Offline
22 posts
since Nov 2007
Nov 13th, 2007
0

Re: Yet another with Security Toolbar infestation!

here's the hijack this logfile

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:25:24 PM, on 11/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\EloSrvce.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\system32\EloDkMon.exe
C:\WINDOWS\system32\EloTTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\TeeTime King\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Link...//www.msn.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {22E58089-6DB5-45D9-BF87-6C8975246D26} - C:\WINDOWS\system32\gebxuvu.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {A95B2816-1D7E-4561-A202-68C0DE02353A} - C:\WINDOWS\system32\hnxkjdav.dll
O2 - BHO: {1cda9a05-511b-df9a-89e4-47621416838e} - {e8386141-2674-4e98-a9fd-b11550a9adc1} - C:\WINDOWS\system32\mkidovjq.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Security Toolbar - {11A69AE4-FBED-4832-A2BF-45AF82825583} - C:\WINDOWS\system32\hnxkjdav.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [OSCD_Creator] c:\Dell\PreODM.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [2439119d] rundll32.exe "C:\WINDOWS\system32\qwuxeaif.dll",b
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\RunOnce: [OSCD_Creator] C:\Dell\PreODM.EXE /2
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AntiSpywareBot] C:\Program Files\AntiSpywareBot\AntiSpywareBot.exe -boot
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase4009.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1119297776359
O16 - DPF: {9F3B4DE4-AA29-11D1-A3D9-FDA4E35D1D25} (IO Control) - http://192.168.1.20/io.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{FDB07B57-C951-4728-B12C-1D83890FE591}: NameServer = 151.197.0.38,199.45.32.28
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: gebxuvu - gebxuvu.dll (file missing)
O20 - Winlogon Notify: hnxkjdav - C:\WINDOWS\SYSTEM32\hnxkjdav.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EloSystemService - Elo Touchsystems, Inc. - C:\WINDOWS\system32\EloSrvce.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe

--
End of file - 6906 bytes
Reputation Points: 10
Solved Threads: 0
Newbie Poster
73firebird is offline Offline
22 posts
since Nov 2007
Nov 13th, 2007
0

Re: Yet another with Security Toolbar infestation!

Download this file from one of the following links :

http://download.bleepingcomputer.com/sUBs/ComboFix.exe
http://www.techsupportforum.com/sectools/combofix.exe

1. Make sure that Combofix is downloaded to and run from, your desktop.

2. Double click combofix.exe & follow the prompts.
3. When finished, ComboFix generates a pop up log which can also be found at C:\ComboFix.txt. Post that log in your next reply, along with a new hijackthis log.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,163 posts
since Feb 2004
Nov 13th, 2007
0

Re: Yet another with Security Toolbar infestation!

first off, thank you for the assistance. this is going to be a bit tedious and drawn out, as i can only commit bits and pieces of my day to working on it. i couldn't get reconnected to the internet (posting from another computer at present) so it shut it down for the night and will have another go it it and doing step two in the morning. thank you!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
73firebird is offline Offline
22 posts
since Nov 2007
Nov 14th, 2007
0

Re: Yet another with Security Toolbar infestation!

Hi;
fate just likes to make my life miserable. it seems that the connection problem is on my providers end, spoke with their tech support today, ran some line checks and found out that it's an outside problem. 24-48 hour repair ticket in with my other nemesis, Verizon. I will likely be posting the combofix results in a few days.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
73firebird is offline Offline
22 posts
since Nov 2007
Nov 15th, 2007
0

Re: Yet another with Security Toolbar infestation!

No worries. It never rains but it pours
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,163 posts
since Feb 2004
Nov 17th, 2007
0

Re: Yet another with Security Toolbar infestation!

ok, so i've gotten my dsl reestablished, but big problem. when i restart or power up from cold, it shows all the normal loading screens but all i get is a bsod. no start menu, desktop icons etc. does the same thing in safe mode. am i totally screwed? it was doing this occasionally the last 2 days working on it, but it always seemed to bring up the desktop after a couple of reboots. now, i get nothing, tried it about 10 times in normal and safe mode. (
Reputation Points: 10
Solved Threads: 0
Newbie Poster
73firebird is offline Offline
22 posts
since Nov 2007
Nov 17th, 2007
0

Re: Yet another with Security Toolbar infestation!

I would try a system repair if you have your XP cd. May also want to attempt a cmos clear by moving the jumpers or removing the mobo battery. One of my pc's would only go as far as the XP logo then quit. Resetting the cmos fixed it.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,163 posts
since Feb 2004
Nov 17th, 2007
0

Re: Yet another with Security Toolbar infestation!

remove & reinstall the battery, or just pull it altogether and start up?
Reputation Points: 10
Solved Threads: 0
Newbie Poster
73firebird is offline Offline
22 posts
since Nov 2007
Nov 17th, 2007
0

Re: Yet another with Security Toolbar infestation!

Remove it for a few minutes, then reinstall it.
Moderator
Featured Poster
Reputation Points: 1142
Solved Threads: 982
Most Valuable Poster
crunchie is offline Offline
12,163 posts
since Feb 2004

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: RUNDLL32 issue
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: jun.exe





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC