Lowyat.NET Forums

Welcome Guest ( Log In | Register )

2 Pages  1 2 > 
RSS feedReply to this topicStart new topicStart Poll

Outline · [ Standard ] · Linear+

> Need help on this hijack log

yhtan
post Jul 22 2008, 01:56 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #1


1234567890
*******

Group: Senior Member
Posts: 3,468
Joined: September 2005





my friend pc had been infected by spyware
below is the hijack log, i can't trace the source and hopefully someone can help me
QUOTE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\NOTEPAD2.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - Default URLSearchHook is missing
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: QXK Olive - {812AE34E-162C-4C94-BAA1-A2C0431AEC84} - C:\WINDOWS\kgxmotapktx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: qndsfmao - {3FCAEB7D-F8AE-4A67-AE6C-57EE1416BB6D} - C:\WINDOWS\qndsfmao.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [TudouVAStart] C:\Program Files\Tudou\·é?ùTudou\TudouVa.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
O4 - Startup: 启动飞速土豆.lnk = Tudou\TudouVa.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: kvxqmtre - {DFA41FDC-288D-44AC-AC5D-521C6ED947BD} - C:\WINDOWS\kvxqmtre.dll
O21 - SSODL: evgratsm - {0087EF3C-B262-47FD-87D7-4522072440E2} - C:\WINDOWS\evgratsm.dll
O23 - Service: Contrl Center of Storm Media (ccosm) - 北京暴风网际科技有限公司 - C:\Program Files\StormII\stormliv.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset  - C:\Program Files\Eset\nod32krn.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 8837 bytes
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
En.Vader
post Jul 22 2008, 10:05 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #2


Regular
**

Group: Junior Member
Posts: 57
Joined: October 2006





C:\WINDOWS\kgxmotapktx.dll
C:\WINDOWS\qndsfmao.dll
C:\WINDOWS\kvxqmtre.dll
C:\WINDOWS\evgratsm.dll

fishy .dll files

C:\Program Files\StormII\stormliv.exe <- what is this?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TristanX
post Jul 22 2008, 10:31 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #3


Enthusiast
*****

Group: Senior Member
Posts: 895
Joined: November 2004
From: Setapak, Kuala Lumpur





Disable System Restore then download and run this:

http://www.malwarebytes.org
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Jul 22 2008, 10:45 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #4


:: pɹɐzıɐʌ ::
*******

Group: Senior Member
Posts: 7,710
Joined: August 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(TristanX @ Jul 22 2008, 10:31 AM)
Disable System Restore then download and run this:

http://www.malwarebytes.org
*


DO NOT EVER DISABLE SYSTEM RESTORE UNTIL THE COMPUTER IS DECLARED CLEAN.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Jul 22 2008, 10:51 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #5


Look at all my stars!!
*******

Group: Senior Member
Posts: 2,919
Joined: June 2005




QUOTE(TristanX @ Jul 22 2008, 10:31 AM)
Disable System Restore then download and run this:

http://www.malwarebytes.org
*


Like eXPeri3nc3 said, do not tell TS to disable System Restore before his computer is really safe!
And do not post the same thing in other people's thread!!

@yhtan
Please post the FULL HijackThis log, including header, and do NOT edit anything in the log.

Tell your friend not to visit China website regularly, or if can, don't even go to China website.

This post has been edited by tan_pang: Jul 22 2008, 10:53 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TristanX
post Jul 22 2008, 10:55 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #6


Enthusiast
*****

Group: Senior Member
Posts: 895
Joined: November 2004
From: Setapak, Kuala Lumpur





It's only temporary to disable system restore. The virus or malware will reinfect if you have it on.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Jul 22 2008, 11:27 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #7


:: pɹɐzıɐʌ ::
*******

Group: Senior Member
Posts: 7,710
Joined: August 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(TristanX @ Jul 22 2008, 10:55 AM)
It's only temporary to disable system restore. The virus or malware will reinfect if you have it on.
*


Erm, what makes you think that it will reinfect if it's on?

Ok, the purpose of not disabling system restore at this current state is to let it act as a safety line / border / net / whatever you call it / so that if else fails there's still system restore.

Shutting it down = one path down the valley = biggest mistake.

I want to know your thoughts.

BTW, we can reset system restore when it's clean, so that the malware inside the sys restore cache gets removed as well.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Jul 22 2008, 11:27 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #8


Look at all my stars!!
*******

Group: Senior Member
Posts: 2,919
Joined: June 2005




QUOTE(TristanX @ Jul 22 2008, 10:55 AM)
It's only temporary to disable system restore. The virus or malware will reinfect if you have it on.
*


No, the files in the System Restore folder will not be executed, and therefore will not reinfect the machine.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Jul 22 2008, 11:28 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #9


:: pɹɐzıɐʌ ::
*******

Group: Senior Member
Posts: 7,710
Joined: August 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(tan_pang @ Jul 22 2008, 11:27 AM)
No, the files in the System Restore folder will not be executed, and therefore will not reinfect the machine.
*


Oi same time reply laugh.gif

Anyway, I have to go. Take over please if needed (give guidance I mean)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TristanX
post Jul 22 2008, 11:34 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #10


Enthusiast
*****

Group: Senior Member
Posts: 895
Joined: November 2004
From: Setapak, Kuala Lumpur





QUOTE(tan_pang @ Jul 22 2008, 11:27 AM)
No, the files in the System Restore folder will not be executed, and therefore will not reinfect the machine.
*


Some virus just restore it back from the folder inside "System Volume Information" after you delete it. That's where System Restore saves it's data. I'm using Symantec's method except for the program.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Jul 22 2008, 11:43 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #11


Look at all my stars!!
*******

Group: Senior Member
Posts: 2,919
Joined: June 2005




QUOTE(TristanX @ Jul 22 2008, 11:34 AM)
Some virus just restore it back from the folder inside "System Volume Information" after you delete it. That's where System Restore saves it's data. I'm using Symantec's method except for the program.
*


This is very funny!!! laugh.gif laugh.gif

The files in System Restore (or System Volume Information) will not restore back unless you tell it to do so!
Those what you said "restore back" is because the computer haven't clean, and it is not related to System Restore

System Restore should be enable always especially when infected with malware. Once something wrong, the system restore with malware is better than no System Restore at all!

This post has been edited by tan_pang: Jul 22 2008, 11:44 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TristanX
post Jul 22 2008, 11:48 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #12


Enthusiast
*****

Group: Senior Member
Posts: 895
Joined: November 2004
From: Setapak, Kuala Lumpur





You cannot stop some malware/virus from copying it back from System Restore files. It will do it once you try to clean it.

Well, you can have it your way. I have mine and I bumped into various malware and virus before. I've also cleaned it manually with my bartpe cd using a 3rd party registry editor before. hehehehe
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Jul 22 2008, 11:53 AM
Show posts by this member only |Rating BETA (0+, 0-) | Post #13


Look at all my stars!!
*******

Group: Senior Member
Posts: 2,919
Joined: June 2005




QUOTE(TristanX @ Jul 22 2008, 11:48 AM)
You cannot stop some malware/virus from copying it back from System Restore files. It will do it once you try to clean it.

Well, you can have it your way. I have mine and I bumped into various malware and virus before. I've also cleaned it manually with my bartpe cd using a 3rd party registry editor before. hehehehe
*


I have tell in previous post
QUOTE
The files in System Restore (or System Volume Information) will not restore back unless you tell it to do so!


Please give me the example of the malware you said can copying back from System Restore
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TristanX
post Jul 22 2008, 12:06 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #14


Enthusiast
*****

Group: Senior Member
Posts: 895
Joined: November 2004
From: Setapak, Kuala Lumpur





I can't really remember the name of the malwares but I think Smitfraud is one of them. I just clean with the most efficient way and forget about it.

I spent hours reading various fixes from various sites on my first encounter.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Jul 22 2008, 12:27 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #15


Look at all my stars!!
*******

Group: Senior Member
Posts: 2,919
Joined: June 2005




QUOTE(TristanX @ Jul 22 2008, 12:06 PM)
I can't really remember the name of the malwares but I think Smitfraud is one of them. I just clean with the most efficient way and forget about it.

I spent hours reading various fixes from various sites on my first encounter.
*


No, Smitfraud can't do that.
The folder System Volume Information is a very secure "locker" that can't let any files get out by themselves, or let any files "B&E".

Anyway, I have tell everything that I can tell. And my advise is still the same: Do NOT disable System Restore.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
redkord
post Jul 22 2008, 12:52 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #16


Regular
**

Group: Junior Member
Posts: 77
Joined: June 2007




TS did u have any spyware/adware remover?
i think there is to many spyware/adware inside ur friend pc..
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Jul 22 2008, 01:48 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #17


:: pɹɐzıɐʌ ::
*******

Group: Senior Member
Posts: 7,710
Joined: August 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(TristanX @ Jul 22 2008, 11:34 AM)
Some virus just restore it back from the folder inside "System Volume Information" after you delete it. That's where System Restore saves it's data. I'm using Symantec's method except for the program.
*


Now, if only I still have sUBs quote regarding Symantec's stupid guide and disabling system restore.

Malware cannot enter the folder System Volume Information. Even you cannot access. How do you think that malware can access the folder inside just like that?

Only SYSTEM can access the folder.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TristanX
post Jul 22 2008, 02:04 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #18


Enthusiast
*****

Group: Senior Member
Posts: 895
Joined: November 2004
From: Setapak, Kuala Lumpur





I could get into System Volume Information folder by changing the ACL. There is even a patch that uses your user name to automatically modify the security of a file to change your half-open connection limit.

Malware or virus gets stronger everytime there is a new one. Hackers can do almost everything when it comes to software. Eventually it can destroy your hard disk just like DH2 did in the old 16-bit days.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tan_pang
post Jul 22 2008, 02:34 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #19


Look at all my stars!!
*******

Group: Senior Member
Posts: 2,919
Joined: June 2005




QUOTE(eXPeri3nc3 @ Jul 22 2008, 01:48 PM)
Now, if only I still have sUBs quote regarding Symantec's stupid guide and disabling system restore.

Malware cannot enter the folder System Volume Information. Even you cannot access. How do you think that malware can access the folder inside just like that?

Only SYSTEM can access the folder.
*


I think even you have the quote now, you can't paste it out for public......

so, lets better just get out from this log and lets TS make the decision whether he want to disable the System Restore or not.

@TristanX
If TS have screw up something and if he have disable System Restore, please teach him how to recover. Thanks
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
eXPeri3nc3
post Jul 22 2008, 02:40 PM
Show posts by this member only |Rating BETA (0+, 0-) | Post #20


:: pɹɐzıɐʌ ::
*******

Group: Senior Member
Posts: 7,710
Joined: August 2005
From: Lurking In The Forum Status: 1+3+3=7





QUOTE(TristanX @ Jul 22 2008, 02:04 PM)
I could get into System Volume Information folder by changing the ACL. There is even a patch that uses your user name to automatically modify the security of a file to change your half-open connection limit.

Malware or virus gets stronger everytime there is a new one. Hackers can do almost everything when it comes to software. Eventually it can destroy your hard disk just like DH2 did in the old 16-bit days.
*


Speaking of ACLs, if they would waste their time changing the SIDs and permissions of the folder, they would rather be nasty and be stagnant on the pc by rootkits or whatever driver protection they can think of.

QUOTE(tan_pang @ Jul 22 2008, 02:34 PM)
I think even you have the quote now, you can't paste it out for public......

so, lets better just get out from this log and lets TS make the decision whether he want to disable the System Restore or not.

@TristanX
If TS have screw up something and if he have disable System Restore, please teach him how to recover. Thanks
*


There are 2 versions of it -- one made in LYN another in TSF. I lost both. sad.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

2 Pages  1 2 >
Bump TopicReply to this topicTopic OptionsStart new topic