PDA

View Full Version : Malicious program unable to fix


rollinpark
08-29-2004, 10:28 PM
hi all,

I have this problem with dialler or trojan i am not sure. My brother did something last time and now i cannot seem to connect to internet. But i manage to connect to net using another hard disk. Weird thing is after connect using the other hard disk, i switch back to the hard disk with the dialler, manage to connect to the net but only for the moment. Next time I boot up and try to connect it failed. Scanning with mcafee turn up nothing.

Previously i do discover there are some malicious program. Ran adaware and fixed it. Now it occured again I think now its even worse. Adaware cannot detect it. Spy Bot do came up with something and fixed all of it but still cannot connect to net. There is this DCO problem that Spy Bot can't seem to fix. It came up everytime i ran spy bot. Hijact This came up with some dialler and i fixed it but still problem persist. My current logs are as below.

Do I need to format my hard disk? I think I have done all I can already.


Logfile of HijackThis v1.97.7
Scan saved at 8:28:04 PM, on 8/29/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v5.00 (5.00.2919.6304)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVSYNMGR.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\3DLDEMON.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGMAIN.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\SPYWAREGUARD\SGBHP.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSSTAT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSHWIN32.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\AVCONSOL.EXE
C:\HJT\HIJACKTHIS.EXE

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\PROGRAM FILES\SPYWAREGUARD\DLPROTECT.DLL
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:\PROGRAM FILES\MCAFEE\MCAFEE VIRUSSCAN\VSCSHELLEXTENSION.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [3DLabsHelperDemon] 3dldemon.exe nowakeup
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [McAfeeVirusScanService] C:\Program Files\McAfee\McAfee VirusScan\AVSYNMGR.EXE
O4 - Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: Net2Phone (HKLM)
O9 - Extra 'Tools' menuitem: Net2Phone (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://127.0.0.1/CFIDE/classes/CFJava.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab

Budfred
08-29-2004, 10:36 PM
I don't see anything bad in your log, but you are running an old version of HJT... Download the latest version from the site linked in my sig and post it to make sure it is clean... In the meanwhile, it would probably also be a good idea to run an online virus scan and download and run the trial version of TrojanHunter to see if they find anything...

Part of the problem is that you are running an outdate version of IE as well and this leaves you vulnerable to any number of attacks.... I wouldn't reformat, you can almost certainly find and kill this thing...

rollinpark
09-06-2004, 01:50 AM
Hi again,

My problem continues. The only way I can connect to the net is by switching between 2 hard disks. The hard discs that cannot connect can connect after i switch to the other hard disc and connect and then reswitch back to the first hard disc. Has anyone experience this before? And another question is what symptoms will i get if my modem got hijack and dial long distance number. Is the problem I described above a symptom?

Thanks again

Budfred
09-06-2004, 02:20 AM
That sounds really odd... did you run the programs I suggested?? Please post the updated version of HJT as I asked so we can see if anything else shows up there...