PDA

View Full Version : Dropper Trojan


ujlee0
08-06-2004, 10:28 PM
I was hoping someone would be able to help me.
I ran Bitdefender and it detected a Trojan (a copy of the log is below).
I tried to clean it by updating Norton and then running it but Norton was unable to clean it so I disabled the system restore, rebooted in safe mode and then ran Trojan Hunter 3.9 (I think this is the latest version) and could not get rid of it. Please let me know what I need to do to get rid of this and prevent it from happening again. I have Sygate, Norton and Trojan Hunter installed and I try to update and run my virus scan at least once a week. Any help and advice anyone can give will be greatly appreciated. Thank you!!

Memory ok
Process [wupdater.exe] [PID:00000218] infected: Adware.KeenValue.A
C:\Program Files\Common files\updater\wupdater.exe unable to disinfect
Master Boot Record 80 ok (Unknown MBR/Boot Code)
Partition Boot 1 (primary) ok (Unknown MBR/Boot Code)
Partition Boot 2 (primary) (active) ok (Windows NT 2000 NTFS)
Partition Boot 3 (primary) ok (Win95 OSR2, Win98 FAT32)
C:\Documents and Settings\James Lee\Application Data\Mozilla\Firefox\Profiles\default.c8m\Cache\3B BFE777d01=>wise0022=>(Upx) infected: Trojan.Dropper.Small.GT
C:\Documents and Settings\James Lee\Application Data\Mozilla\Firefox\Profiles\default.c8m\Cache\BC 1B5815d01=>wise0022=>(Upx) infected: Trojan.Dropper.Small.GT
C:\Documents and Settings\James Lee\Application Data\Mozilla\Firefox\Profiles\default.c8m\Cache\E4 20AD55d01=>wise0017=>(Upx) infected: Trojan.Dropper.Small.GT
C:\Documents and Settings\James Lee\Application Data\Mozilla\Firefox\Profiles\default.c8m\Cache\FB 70CB2Ad01=>wise0017=>(Upx) infected: Trojan.Dropper.Small.GT
C:\Documents and Settings\James Lee\Local Settings\Temporary Internet Files\Content.IE5\GT67WTMN\htpridewp[1].exe=>wise0022=>(Upx) infected: Trojan.Dropper.Small.GT
C:\Program Files\Common Files\updater\delupdat.exe infected: Trojan.Downloader.KeenValue.A
C:\Program Files\Common Files\updater\delupdat.exe unable to disinfect
C:\Program Files\Common Files\updater\sui.exe infected: Trojan.Downloader.KeenValue.C
C:\Program Files\Common Files\updater\sui.exe unable to disinfect
C:\Program Files\Common Files\updater\wupdater.exe infected: Adware.KeenValue.A
C:\Program Files\Common Files\updater\wupdater.exe unable to disinfect
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll infected: Trojan.Downloader.KeenValue.A
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll unable to disinfect
C:\Program Files\IncrediFind\BHO\Tipb.exe infected: Adware.KeenValue.B
C:\Program Files\IncrediFind\BHO\Tipb.exe unable to disinfect
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP35\A0003730.exe=>wise0017=>(Upx) infected: Trojan.Dropper.Small.GT
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP35\A0003731.exe=>wise0017=>(Upx) infected: Trojan.Dropper.Small.GT
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP35\A0003732.exe=>wise0022=>(Upx) infected: Trojan.Dropper.Small.GT
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP35\A0003733.exe=>wise0022=>(Upx) infected: Trojan.Dropper.Small.GT
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP36\A0003962.dll infected: Application.Adware.NewDotNet.B
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP36\A0003962.dll unable to disinfect
C:\updaterInstall_112.exe infected: Backdoor.Blarul.D
C:\updaterInstall_112.exe unable to disinfect
C:\WINDOWS\iTopRebates\60wu82rd.exe=>(Upx) infected: Trojan.Dropper.Small.GT
C:\WINDOWS\iTopRebates\60wu82rd.exe=>(Upx) unable to disinfect
C:\WINDOWS\SYSTEM32\ATPartners.dll infected: Trojan.Downloader.Rameh.C
C:\WINDOWS\SYSTEM32\ATPartners.dll unable to disinfect
C:\WINDOWS\SYSTEM32\sahagent1020.exe infected: Adware.Sahagent.A
C:\WINDOWS\SYSTEM32\sahagent1020.exe unable to disinfect
C:\WINDOWS\SYSTEM32\setup_incred_3.exe infected: Trojan.Downloader.KeenValue.A
C:\WINDOWS\SYSTEM32\setup_incred_3.exe unable to disinfect

PrntRhd
08-06-2004, 11:25 PM
I searched while waiting for the HJT experts and only found one hit on Google: here (http://computercops.biz/postp257463.html)

classicsoftware
08-06-2004, 11:46 PM
Please download Hijack This (http://www.subratam.org/?page=removal). Please it in a permanent folder.

Run The program

Choose scan.

Choose save log.

Post the contents of the log here, do not attched, post the log direectly into the thread.

Budfred
08-07-2004, 01:44 AM
You are going to need to reset System Restore and you probably need to run spyware scans also... Most of what you have can be cleaned with HJT, but you might as well clean up what you can first....

ujlee0
08-07-2004, 11:36 AM
I ran SpyBlaster and SpyBot Search and Destroy. I reset my System Restore and ran HJT.
Below is my HJT log. Please take a look and advice me what to do next. Thank you all for your help!

Logfile of HijackThis v1.98.0
Scan saved at 10:32:13 AM, on 8/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C 1.EXE
C:\Program Files\NoAds\NoAds.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\James Lee\Desktop\Internet Security\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - Default URLSearchHook is missing
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C 1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - [url]http://wwws.musicmatch.com/mmz/openWebRadio.html[/url] (file missing)
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - [url]http://www.webshots.com/samplers/WSDownloader.ocx[/url]
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - [url]http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab[/url]
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - [url]http://www.bitdefender.com/scan/Msie/bitdefender.cab[/url]

shanmuga
08-08-2004, 02:56 AM
Uninstall the following program through Add/Remove programs;

Web_Rebates

Have HijackThis fix the following by placing a check in the appropriate boxes and selecting fix checked, also make sure that all browser and windows explorer windows are closed before fixing.

R3 - Default URLSearchHook is missing
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm

Make sure you can view (http://www.xtra.co.nz/help/0,,4155-1916458,00.html) hidden and system files. Reboot into Safeboot (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam) and delete the folder if found;

C:\Program Files\Web_Rebates<----- This folder.

Reboot into normal mode, do a full system scan with TrojanHunter & Bitdefender after checking for updates.

Download the latest version of HijackThis 1.98.2 (http://www.majorgeeks.com/download3155.html), post a freshlog and say if problems persist.

ujlee0
08-09-2004, 12:49 AM
ok. I ran HJT and fixed the stuff you've mentioned. Then enabled view hidden files; rebooted in safe mode and could not find the Web_rebates folder so I assumed there wasn't any. I rebooted to normal mode and ran Trojan Hunter. Trojan Hunter did not find anything. I ran BitDefender and it found the same stuff as before. The BitDefend log and the new HiJackThis (new v1.98.2) log is below. Please advice what to do next. Thanks again!

Logfile of HijackThis v1.98.2
Scan saved at 11:35:13 PM, on 8/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
c:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C 1.EXE
C:\Program Files\NoAds\NoAds.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HiJackThis\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Web assistant - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Web assistant - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] c:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [EPSON Stylus C64 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2C 1.EXE /P23 "EPSON Stylus C64 Series" /O6 "USB001" /M "Stylus C64"
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [NoAds] "C:\Program Files\NoAds\NoAds.exe"
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - [url]http://wwws.musicmatch.com/mmz/openWebRadio.html[/url] (file missing)
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6A52B394EC3B} (WSDownloader Control) - [url]http://www.webshots.com/samplers/WSDownloader.ocx[/url]
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - [url]http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab[/url]
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - [url]http://www.bitdefender.com/scan/Msie/bitdefender.cab[/url]

BitDefender Log
Master Boot Record 80 ok (Unknown MBR/Boot Code)
Partition Boot 1 (primary) ok (Unknown MBR/Boot Code)
Partition Boot 2 (primary) (active) ok (Windows NT 2000 NTFS)
Partition Boot 3 (primary) ok (Win95 OSR2, Win98 FAT32)
C:\Documents and Settings\James Lee\Local Settings\Temporary Internet Files\Content.IE5\GT67WTMN\htpridewp[1].exe=>wise0022=>(Upx) infected: Trojan.Dropper.Small.GT
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll infected: Trojan.Downloader.KeenValue.A
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll unable to disinfect
C:\Program Files\IncrediFind\BHO\Tipb.exe infected: Adware.KeenValue.B
C:\Program Files\IncrediFind\BHO\Tipb.exe unable to disinfect
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000016.exe infected: Adware.KeenValue.A
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0000016.exe unable to disinfect
C:\updaterInstall_112.exe infected: Backdoor.Blarul.D
C:\updaterInstall_112.exe unable to disinfect
C:\WINDOWS\SYSTEM32\ATPartners.dll.tcf infected: Trojan.Downloader.Rameh.C
C:\WINDOWS\SYSTEM32\ATPartners.dll.tcf unable to disinfect
C:\WINDOWS\SYSTEM32\sahagent1020.exe infected: Adware.Sahagent.A
C:\WINDOWS\SYSTEM32\sahagent1020.exe unable to disinfect
C:\WINDOWS\SYSTEM32\setup_incred_3.exe infected: Trojan.Downloader.KeenValue.A
C:\WINDOWS\SYSTEM32\setup_incred_3.exe unable to disinfect

shanmuga
08-09-2004, 04:50 AM
AFAIK, there is nothing wrong with your HijackThis log, it looks like the Bitdefender scan is tagging remnants and files in TIF and System restore.

Download and scan your system with adaware following instructions here, How to Configure Adaware6 for Full/Custom Scan (http://www.pcguide.com/vb/showthread.php?s=&amp;threadid=31406)

Make sure you can view (http://www.xtra.co.nz/help/0,,4155-1916458,00.html) hidden and system files. Reboot into Safeboot (http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&amp;src=sec_doc_nam) and delete the following files and folders, if found, in Windows explorer.

C:\Program Files\IncrediFind<------This folder
C:\updaterInstall_112.exe <-------This file
C:\WINDOWS\SYSTEM32\sahagent1020.exe<----This file
C:\WINDOWS\SYSTEM32\setup_incred_3.exe<----This file
C:\WINDOWS\SYSTEM32\ATPartners.dll.tcf<----This file

TrojanHunter I believe, adds .tcf extn to the the files it can't delete. You may have to rename it back to ATPartners.dll to be able to delete it.

Finally clear the TIF/Temp folders and reset system restore.

From your HijackThis log, I can't find any info on this one.
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper

Do you know what it is? If you don't know, look for a folder P17Helper and/or a file P17.dll, right click and check the properties and post all of what you see.

ujlee0
08-09-2004, 09:10 AM
I configured Adaware for a full scan and scanned and fixed the files it has suggested. I enabled view hidden files and rebooted in safe mode and tried to find and delete the files you have suggested. The only one I found and deleted was: "C:\Program Files\IncrediFind". Could not find the rest. Also, I'm not sure what TIF/TEMP file you're refering to so I didn't clear it as you have suggested.

As for P17.dll, this is what I saw. Am I clean of spyware and what I thought was a trojan now? Thanks again for all your help!

Application Extention
Location: C:\I386
Size: 59.5 KB (60,928 bytes)
Size on Disk: 59.5 KB (60,928 bytes)
Created: Friday, July 30, 2004, 6:13:33 PM
Modified: Thursday, June 10, 2004, 12:51:00 PM
Accessed: Today, August 09, 2004, 7:09:45 AM

Version: 1.0.1.30
Description: P17 AudioControlX2 Module

shanmuga
08-10-2004, 03:04 AM
TIF = Temporary Internet files
TEMP = Files in your various TEMP folders, empty them and also disable system restore and enable it on reboot, to clear the system volume information. :)