I am unsure how this all happened left my computer on and went somewhere.. Now i have several files.. heres my hijack this report: please someone help because i do not have a windows cd to reformat. My computer was built for me so i never got one..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:05:33 PM, on 7/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://internetsearchservice.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://internetsearchservice.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {1C2DA439-4680-4E85-A22D-EB2385FABF80} - C:\WINDOWS\system32\mlJYssRi.dll
O2 - BHO: (no name) - {5C11AF96-17DF-4B70-9BCB-4470E158BECD} - C:\WINDOWS\system32\geBuRIYq.dll
O2 - BHO: C:\WINDOWS\system32\kdfgj83ke.dll - {C5AF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\kdfgj83ke.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [lphcpu3j0erb3] C:\WINDOWS\system32\lphcpu3j0erb3.exe
O4 - HKLM\..\Run: [wekewfjo983mkefdd] C:\DOCUME~1\Robert\LOCALS~1\Temp\winlogan.exe
O4 - HKLM\..\Run: [DelayLoad] C:\DOCUME~1\Robert\LOCALS~1\Temp\atmadm2.exe
O4 - HKLM\..\Run: [winsock32] C:\WINDOWS\system32:winsock32.exe
O4 - HKLM\..\Run: [BM878ef6ee] Rundll32.exe "C:\WINDOWS\system32\xhhwmapd.dll",s
O4 - HKCU\..\RunOnce: [NeroHomeFirstStart] C:\Program Files\Common Files\Ahead\Lib\NMFirstStart.exe
O4 - HKUS\S-1-5-18\..\Run: [wblogon] C:\WINDOWS\system32\ubpr01.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [wblogon] C:\WINDOWS\system32\ubpr01.exe (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
O20 - Winlogon Notify: mlJYssRi - C:\WINDOWS\SYSTEM32\mlJYssRi.dll
O20 - Winlogon Notify: winctrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O21 - SSODL: kvxqmtre - {D038121F-EAF1-4613-8F92-927D23FF62AB} - C:\WINDOWS\kvxqmtre.dll
O21 - SSODL: evgratsm - {7B46B05A-93A0-46A9-ABD8-E8C742C915F8} - C:\WINDOWS\evgratsm.dll
O22 - SharedTaskScheduler: werkjdnfi8wnkjmdfdfkefn - {C5AF49A2-94F3-42BD-F434-3604812C897D} - C:\WINDOWS\system32\kdfgj83ke.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iolo FileInfoList Service (iolofileinfolist) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (iolosystemservice) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Microsoft security update service (msupdate) - Unknown owner - c:\windows\system32\mssrv32.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe

--
End of file - 5471 bytes

Dani AI

Generated

Brief expert summary tied to the thread: s HijackThis output and the report of many resurrecting files plus the broken LSP/winsock behavior point to a persistent trojan/rootkit that altered Run keys and networking components. was correct to suggest on-demand scanners and a Winsock repair — those are good first moves — but the core problem is persistence and an impaired network stack that prevents signature updates.

Immediate, safe actions (in order)

  • Physically disconnect the machine from the network to stop data exfiltration and spread.
  • From Safe Mode or a normal command prompt, attempt a Winsock/TCP reset. Run the commands below, then reboot and check connectivity:
netsh winsock reset
netsh int ip reset c:\resetlog.txt
ipconfig /flushdns
ipconfig /release
ipconfig /renew

If these commands fail or networking remains nonfunctional, do not try repeated online scans on the infected box.

When local repairs fail

  • Use a known-clean computer to download rescue tools and antivirus rescue ISOs. Boot the infected PC from a rescue environment or scan the drive by connecting it to the clean machine as a secondary disk. Offline scanning removes drivers and hidden files that survive normal Windows boots.
  • Run specialized rootkit scanners (rescue disk scanners or vendor-rootkit removers) because registry Run entries and DLLs in System32 that reappear after removal usually indicate a kernel/rootkit component.

Data safety and next steps

  • Back up only personal documents (no .exe/.msi/.scr) to external media and scan those backups separately before restoring.
  • If malware remains stubborn or system files are corrupted, plan a full wipe and reinstall. Without original media, obtain recovery media from the system builder/manufacturer or use legitimate installation media matching the licensed OS.
  • Assume credentials were exposed: change important passwords from a clean device and monitor financial accounts.

If uncertainty remains or rootkit signs persist, consider professional offline assistance before further attempts to run online updates on the infected machine.

Recommended Answers

All 3 Replies

Hi and welcome to the Daniweb forums :).

==========

Download Malwarebytes' Anti-Malware (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html) to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Make sure that you restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

Post new HJT log.

Ok i did all that, but my problem is that i think that something that the virus did in my registry messed up my network connection, because my computer is not reading anything from my ethernet port, and it comes up with the "play" ip address and is leaving me with no or limited connectivity... So i cant update the definitions.. So everytime i restart 25 of the files keep coming back, and keep causing havok

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.