Wilders Security Forums  

Go Back   Wilders Security Forums > Browser Hijacks and Spyware Problems > adware, spyware & hijack cleaning
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Spyware Cleaning Section Closed!!
Notice: The spyware cleaning (HijackThis) section is closed. Wilders Security no longer provides one on one spyware cleaning assistance. Please see this announcement for a list of websites that provide such services.
 
 
Thread Tools Search this Thread
  #1  
Old July 7th, 2004, 06:15 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default [done]Trojan Horse BackDoor.Agent.BA.

Ok working on a friends computer and he's had this one for awhile.

AVG pops up about 10 times on startup with the following virus.
Trogan Horse BackDoor.Agent.BA
in
C:\windows\system32\comfc.dll

AVG cannot heal it or remove it to virus vault as the file is in use. Restarting in safe mode and running AVG still wont fix it.
I've run both Ad Aware and SD Spybot (amazing how much junk they find between them) but the virus is still popping up.

Anyway heres the HijackThis log.

Hope you can help.

Logfile of HijackThis v1.97.7
Scan saved at 11:08:27, on 07/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {858044B9-1583-42E1-A34C-4B13EA6E09F5} - C:\WINDOWS\System32\dfoaf.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [rundll32] C:\windows\rundll32.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {11111111-1111-1111-1111-111111111732} - file://c:\progra~1\pl.exe
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC95EC47-8E7D-4398-A513-2B44FFEF40B4}: NameServer = 195.92.195.95 195.92.195.94
  #2  
Old July 7th, 2004, 08:04 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Hello Smallfry,

Download and install APM from: http://www.diamondcs.com.au/index.php?page=apm

Run Hijackthis again with all browsers closed and check these items and then on Fix:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\dfoaf.dll/sp.html (obfuscated)

O2 - BHO: (no name) - {858044B9-1583-42E1-A34C-4B13EA6E09F5} - C:\WINDOWS\System32\dfoaf.dll (file missing)

O4 - HKCU\..\Run: [rundll32] C:\windows\rundll32.exe

O16 - DPF: {11111111-1111-1111-1111-111111111732} - file://c:\progra~1\pl.exe

Don't reboot yet.

Open the program you downloaded (APM)
In the upper window select explorer.exe
In the lower window find and rightclick C:\WINDOWS\System32\dfoaf.dll
Select Unload DLL and click OK on the prompts that follow.

Reboot and scan with AdAware (the first program you downloaded)

Reboot. Now, do the following

Copy the contents of the quote box to Notepad.
Name the file Appinit.bat
Save as type All Files
Save on the Desktop.

Quote:
Reg save "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows" windows1.hiv
ren windows1.hiv windows.txt



Double click on Appinit.bat
This will create a file on the desktop named windows.txt
Copy and paste that log here along with a new HJT log.
  #3  
Old July 8th, 2004, 05:55 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

Quote:
Originally Posted by Taz71498
Open the program you downloaded (APM)
In the upper window select explorer.exe
In the lower window find and rightclick C:\WINDOWS\System32\dfoaf.dll
Select Unload DLL and click OK on the prompts that follow.

Ok I tried this however C:\windows\system32\dfoaf.dll was not listed under explorer.exe

Here are the log files from Hijack this

Logfile of HijackThis v1.97.7
Scan saved at 10:10:22, on 08/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=http://www-cache.freeserve.com:8080;ftp=http://www-cache.freeserve.com:8080
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin.cab

I've attached the windows.txt file you had me make as it just shows jibberish to me
Attached Files
File Type: txt windows.txt (8.0 KB, 30 views)
  #4  
Old July 8th, 2004, 04:57 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Hello,

Yes the file does look like jibberish, but could I ask you to do something.
Could you copy and paste that window.txt file here instead of attaching the file this time. One of my computers does not show the file properly and I am finding it easier to just do the copy and paste.
  #5  
Old July 9th, 2004, 03:38 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

regf       Pugf hbin  nk, Y.   x 0 < 0 x  Windows sk x x            !    !  ?          ?               vk     UDeviceNotSelectedTimeout1 5  (  h vk  '   zGDIProcessHandleQuota"9 0  =tvk     Spooler2y e s
_vk    5swapdisk h    X vk     . TransmissionRetryTimeoutvk  '   p USERProcessHandleQuota4 h    X   vk <    AppInit_DLLs C : \ W I N D O W S \ S y s t e m 3 2 \ c o m f c . d l l
  #6  
Old July 9th, 2004, 08:46 AM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Hello,

Well, we have ourselves a hidden dll that we will have to get rid of.

There is some info I need from you first. Do you have XP home or XP professional?

Is your system file NTFS or Fat32? (To check this, all you need to do is go to Start>My computer>Highlight your C drive and Right click on it and choose properties. You will see File System near the top and it will tell you if it is NTFS or Fat32.)

When you give me the info. we will proceed on getting rid of that dll or your problem will just come back.
  #7  
Old July 9th, 2004, 11:18 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

Unfortunatly I cant work on the computer for a week now. The friend who owns the PC has gone to spain for a week and taken his PC home. Sorry to jerk you about but I'll get back to you once I can get my grubby mitts on his PC again.

I know he has XP home and I think he has NTFS but I cant confirm that yet.
  #8  
Old July 9th, 2004, 01:42 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

No problem,

We will be here
  #9  
Old July 20th, 2004, 04:46 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

Ok.

He has NTFS and Xp Home edition.
  #10  
Old July 23rd, 2004, 04:35 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Hello,

I'm back. I went on vacation and just got back last night. Sorry for the delay.

Here is the next step:

Copy the contents of this quote box into note pad and save it as hiving.bat

Quote:
@echo off
Echo Working

Reg Query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v Appinit_Dlls
If ERRORLEVEL==1 GoTo End
GoTo DOIT
:End

echo >not.vbs MsgBox "No Appinit_Dlls value Present" ^& vbcrlf ^& "Removal Aborted"
Wscript.exe not.vbs
del not.vbs
Exit

OIT
If exist backup.hiv del backup.hiv
If exist f.hiv del f.hiv

reg save "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" backup.hiv
ne

PING 1.1.1.1 -n 2 -w 1000 >NUL
if not exist backup.hiv goto one

Reg Delete "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /f


Reg add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows"
:Notthere

PING 1.1.1.1 -n 2 -w 1000 >NUL
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows"
IF ERRORLEVEL ==1 Go to Notthere

reg Restore "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows" backup.hiv

:two

PING 1.1.1.1 -n 2 -w 1000 >NUL
Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows" /v Appinit_Dlls
IF ERRORLEVEL==1 GOTO two

reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows" /v Appinit_Dlls /f
:appy

PING 1.1.1.1 -n 2 -w 1000 >NUL
Reg Query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows" /v Appinit_Dlls
If Not ERRORLEVEL==1 GOTO appy

Reg save "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows" f.hiv
:three

PING 1.1.1.1 -n 4 -w 1000 >NUL
if not exist f.hiv GOTO three

Reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\NotWindows" /f

Reg Add "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
:four

PING 1.1.1.1 -n 1 -w 1000 >NUL
Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows"
If ERRORLEVEL==1 GOTO four

:five



PING 1.1.1.1 -n 2 -w 1000 >NUL
Reg Restore "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" f.hiv
Reg Query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows" /v USERProcessHandleQuota
If ErrorLevel==1 GOTO five

If exist f.hiv ren f.hiv fbackup.hiv

Echo > finished.vbs MsgBox "Done"
Wscript.exe finished.vbs
del finished.vbs

Now, open and run hiving.bat.

If you have script blocking enabled you will get a warning. Please allow this to run. The script is just producing a message box. Double click on the batch to run it. After a reboot the super hidden nasty file will no longer be loaded and will be visible. This will end the constant reinstall of about:Blank.

----------------------
You run Home and so you will restart into Safe mode.

Restart into Safe mode and find this file:
C:\WINDOWS\System32\comfc.dll

Use the security tab on comfc.dll and take ownership.
Change the 'everyone special' to
'you> with Admin rights-> FULL control
Then try to delete it, if that fails try to rename
it first to different name+ext.
Example:
log.dll>bleh.txt
bleh.txt > badfile.111

Once you have successfully deleted the file restart into Regular Windows mode.

Extract and Run CWShredder immediately.
Press the fix button to clean.

Restart and run hijackThis again.

Post your new log here in your next reply.

Also please create a new Windows.txt and attach it so we can doublecheck.
  #11  
Old July 29th, 2004, 06:16 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

hey. hope you had a nice holiday.

Threw me a little bit to start with till I realised the forum had changed the program with smileys. Once I fixed them it all ran ok.

Heres the Hijakthis log.

Logfile of HijackThis v1.97.7
Scan saved at 11:10:58, on 29/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://freeola.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://freeola.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O14 - IERESET.INF: START_PAGE_URL=http://freeola.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeup...ntent/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin.cab

And here is the Windows.txt

regf       Pugf hbin  \ W I N D O W S \ s *nk, Ru   0 < 0 x  Windowsowssk            !    !  ?          ?               Z vk  *   UDeviceNotSelectedTimeout1 5  (  p vk  '   zGDIProcessHandleQuota"9 0  =tvk     Spooler2y e s
_vk    5swapdisk p   ( ` vk     . TransmissionRetryTimeoutvk  '   p USERProcessHandleQuota4 p   ( `  d
e e e e e e e e f f f f f f f f f g g g g g g g g g h h h h h h h h h i i i i i i i i j j j j j j j j j k k k k k k k k k l l l l l l l l l m m m m m m m m m n n n n n n n n n o o o o o o o o o p p p p p p p p p q q q q q q q q q r r r r r r r r r s s s s s s s s s t t t t t t t t t u u u u u u u u u v v v v v v v v v w w! w! w! w! w! w! w! w! x! x! x" x" x" x" x" x" x" y" y" y# y# y# y# y# y# y# z# z# z# z$ z$ z$ z$ z$ z$ {$ {$ {$ {$ {% {% {% {% {% |% |% |% |% |& |& |& |& |& }& }& }& }& }& }' }' }' }' ~' ~' ~' ~' ~' ~( ~( ~( ~( ( ( ( ( ( ( ) ) ) ) ) ) ) ) ) * * * * * * * * * * + + + + + + + + + , , , , , , , , , , - - - - - - - - - . . . . . . . . . . / / / / / / / / / 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 1 1 1 1 1 2 2 2 2 2 2 2  08X?8X?3 3 3 3 3 3 3 3 4 4 4 4 4 4 4 4 4 5 5 5 5 5 5 5 5 5 5 6 6 6 6 6 6 6 6 6 7 7 7 7 7 7 7 7 7 7 8 8 8 8 8 8 8 8 8 9 9 9 9 9 9 9 9 9 9 : : : : : : : : : ; ; ; ; ; ; ; ; ; ; < < < < < < < < < T T T T T T T T T U U U U U U U U U V V V V V V V V V W W W W W W W W W X X X X X X X X X Y Y Y Y Y Y Y Y Y Z Z Z Z Z Z Z Z Z [ [ [ [ [ [ [ [ [ \ \ \ \ \ \ \ \ \ ] ] ] ] ] ] ] ] ] ^ ^ ^ ^ ^ ^ ^
^
^
_
_
_
_
_
_
_ _ _ ` ` ` ` ` ` ` ` ` a a a a mGh051  PS   11  xE* N(TO'}O&
{O&
{O&
{O&
{O&
{O&
{O&
{O&
{O&
{O&
{O&
{P&
|I%
}D% KO3U5 Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#X8$t>L'
aKA R)S+
_I= Q(S+
_I= HHHHHH HHH Q(S+
_I= HHHHHH HHH Q(S+
[E: HHH Q(S+
[E: HHHHHH HHH Q(S+
_I= HHHHHH Q(S+
^J@ Q)S,
*uDpZ1v]3v]3v]3v]3v]3v]3v]3v]3v_9v_8v_9l^AP*L%v[*O_\9H E
i.k1j0j0j0j0j0j0j0o6n5p7k;IG& *g:J
K KKKKKKKJJKK
@! *

at least AVG isnt throwing a fit everytime a program starts now.
  #12  
Old July 29th, 2004, 05:50 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Oh for crying out load, I can't believe I did that. I meant to wrap that quote in Code tags, not Quote tags. Sorry, glad you figured it out.

Run HJT again and check these and then on Fix:

O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit

O16 - DPF: {F57D17AE-CE37-4BC8-B232-EA57747BE5E7} - http://66.98.176.62/EPlugin.cab

Reboot and post a new log here for final review.
  #13  
Old August 5th, 2004, 04:38 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

ugh, getting the PC off him to finnish this was like pulling teeth. Anyway, heres the log.

Logfile of HijackThis v1.97.7
Scan saved at 09:32:33, on 05/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINDOWS\System32\wuauclt.exe
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://freeola.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://freeola.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB002" /M "Stylus Photo RX500"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O14 - IERESET.INF: START_PAGE_URL=http://freeola.com
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com...45/yacscom.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeup...ntent/opuc.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
  #14  
Old August 5th, 2004, 04:49 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Hello,

The log looks good. How are things working now?
  #15  
Old August 9th, 2004, 03:36 AM
Smallfry Smallfry is offline
Infrequent Poster
 
Join Date: Jun 2004
Posts: 10
Default Re: Trojan Horse BackDoor.Agent.BA.

Heya,

Everything seems to be running ok now. Its even stopped trying to dial out on boot up.

Thanks for all your help
  #16  
Old August 9th, 2004, 03:58 PM
Taz71498's Avatar
Taz71498 Taz71498 is offline
Spyware Expert
 
Join Date: May 2004
Location: USA
Posts: 674
Default Re: Trojan Horse BackDoor.Agent.BA.

Glad we were able to help.

Here is a link for you to go to that will give you suggestions on how to keep your computer safe:
http://www.wilderssecurity.com/showthread.php?t=27971

Happy Surfing!
 

Wilders Security Forums > Browser Hijacks and Spyware Problems > adware, spyware & hijack cleaning « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:23 PM.


Powered by vBulletin Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright 2002 - 2013, Wilders Security Forums