orangealert Posted February 9, 2009 ID:54978 Share Posted February 9, 2009 Logfile of Trend Micro HijackThis v2.0.2Scan saved at 14:10:15, on 09/02/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16762)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Acer\Empowering Technology\admServ.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exeC:\WINDOWS\system32\CTsvcCDA.exeC:\Program Files\Creative\Shared Files\CTDevSrv.exeC:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exeC:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exeC:\Program Files\F-Secure\Anti-Virus\fsgk32st.exeC:\Program Files\F-Secure\Common\FSMA32.EXEC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXEC:\Program Files\F-Secure\Common\FSMB32.EXEC:\Program Files\Intel\Wireless\Bin\RegSrvc.exeC:\Program Files\CyberLink\Shared Files\RichVideo.exeC:\Program Files\F-Secure\Common\FCH32.EXEC:\WINDOWS\system32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exeC:\Program Files\F-Secure\Anti-Virus\fsqh.exeC:\Program Files\F-Secure\Common\FAMEH32.EXEC:\Program Files\F-Secure\FSPC\fspc.exeC:\Program Files\F-Secure\FSAUA\program\fsaua.exeC:\Program Files\F-Secure\Anti-Virus\fssm32.exeC:\Program Files\F-Secure\FWES\Program\fsdfwd.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Acer\Acer Arcade\PCMService.exeC:\Acer\Empowering Technology\eRecovery\Monitor.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Acer\Empowering Technology\eDataSecurity\eDSloader.exeC:\acer\Empowering Technology\ePower\epm-dm.exeC:\PROGRA~1\LAUNCH~1\QtZgAcer.EXEC:\Acer\Empowering Technology\admtray.exeC:\WINDOWS\V0220Mon.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exeC:\Program Files\F-Secure\Common\FSM32.EXEC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\iTunes\iTunesHelper.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\F-Secure\FSAUA\program\fsus.exeC:\Program Files\Creative\Creative Media Lite\CTZDetec.exeC:\Program Files\Creative\Software Update 3\SoftAuto.exeC:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exeC:\WINDOWS\system32\igfxext.exeC:\Program Files\F-Secure\FSGUI\fsguidll.exeC:\WINDOWS\system32\igfxsrvc.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\F-Secure\Anti-Virus\fsav32.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\WINDOWS\services.exeC:\WINDOWS\system32\svschost.exeC:\WINDOWS\sysguard.exeC:\WINDOWS\system32\sv Link to post Share on other sites More sharing options...
Tigger93 Posted February 9, 2009 ID:55000 Share Posted February 9, 2009 Hi. Download ComboFix from one of the locations below, and save it to your Desktop. Link 1Link 2 Double click combofix.exe and follow the prompts. Please, never rename Combofix unless instructed.When finished, it shall produce a log for you. Post that log and a HijackThis log in your next replyNote: Do not mouseclick Combofix's window while its running. That may cause it to stall Link to post Share on other sites More sharing options...
orangealert Posted February 10, 2009 Author ID:55225 Share Posted February 10, 2009 Hi, thanks for the reply. I have not been able to download the fix tool as any attempt to access a webpage is blocked by this bleeping virus! So I am having to contact you via another pc... Please can you help with a way I can regain control of my web browser long enough to be able to begin disinfection?Cheers! Link to post Share on other sites More sharing options...
Tigger93 Posted February 10, 2009 ID:55297 Share Posted February 10, 2009 Can you download the tool to a flash drive or CD, and take it to the infected PC and try to run ti? Link to post Share on other sites More sharing options...
orangealert Posted February 11, 2009 Author ID:55555 Share Posted February 11, 2009 Hi, after a bit of a nightmare evening where the pc kept shutting down on startup, factory settings were eventually restored today. All appears to be well again. MBAM states I am clean, and here is the HJT Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:20:34 PM, on 2/11/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Intel\Wireless\Bin\EvtEng.exeC:\Program Files\Intel\Wireless\Bin\S24EvMon.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Synaptics\SynTP\SynTPLpr.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Acer\Acer Arcade\PCMService.exeC:\Acer\Empowering Technology\admServ.exeC:\WINDOWS\system32\igfxtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\Acer\Empowering Technology\eDataSecurity\eDSloader.exeC:\acer\Empowering Technology\ePower\epm-dm.exeC:\PROGRA~1\LAUNCH~1\QtZgAcer.EXEC:\Acer\Empowering Technology\admtray.exeC:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exeC:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exeC:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exeC:\WINDOWS\system32\igfxext.exeC:\Program Files\Intel\Wireless\Bin\RegSrvc.exeC:\WINDOWS\system32\igfxsrvc.exeC:\Program Files\CyberLink\Shared Files\RichVideo.exeC:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exeC:\WINDOWS\system32\wscntfy.exeC:\WINDOWS\System32\svchost.exeC:\Acer\Empowering Technology\eRecovery\Monitor.exeC:\WINDOWS\system32\CTFMON.EXEC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Documents and Settings\Anthony\Desktop\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.acer.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.comO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO3 - Toolbar: Acer eDataSecurity Management - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - C:\WINDOWS\system32\ToolBand.dllO4 - HKLM\..\Run: [LaunchApp] AlaunchO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXEO4 - HKLM\..\Run: [synTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exeO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNCO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exeO4 - HKLM\..\Run: [EPM-DM] c:\acer\Empowering Technology\ePower\epm-dm.exeO4 - HKLM\..\Run: [Acer ePower Management] C:\Acer\Empowering Technology\ePower\Acer ePower Management.exe bootO4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\QtZgAcer.EXEO4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exeO4 - HKLM\..\Run: [ADMTray.exe] "C:\Acer\Empowering Technology\admtray.exe"O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silentO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXEO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO8 - Extra context menu item: &Sample Toolband Serach - res://C:\WINDOWS\system32\ToolBand.dll/MENUSEARCH.HTMO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: AdminWorks Agent X6 (AWService) - Avocent Inc. - C:\Acer\Empowering Technology\admServ.exeO23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exeO23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exeO23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exeO23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exeO23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exeO23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe--End of file - 5626 bytes Link to post Share on other sites More sharing options...
Tigger93 Posted February 11, 2009 ID:55653 Share Posted February 11, 2009 Thanks, it would have been fixable but your choice. It's clean. Link to post Share on other sites More sharing options...
Recommended Posts