CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[FIXED]Hi-jack Log help

 
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
DDS

Cadet
Cadet


Joined: Sep 24, 2004
Posts: 9
Location: USA

PostPosted: Fri Sep 24, 2004 4:58 pm    Post subject: Hi-jack Log help
Reply with quote

Hello guys pretty sure i have a virus as sysoverload.exe seems dodgy but would ask for help before i delete also is \RunServices: [Win32 USB2 service] winsound1.exe ok? and O4 - HKLM\..\RunServices: [Windows OEM Tool] wnres.exe

Anyway here is the log, thanks for any help you provide:

Code:
Logfile of HijackThis v1.97.7
Scan saved at 18:06:30, on 24/09/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\logonui.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
G:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NetLimiter\NetLimiter.exe
C:\Program Files\QuickTime\qttask.exe
C:\mysql\bin\mysqld-nt.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Ad-aware 6\Ad-watch.exe
G:\WINDOWS\system32\service.exe
G:\WINDOWS\system32\csrs.exe
G:\WINDOWS\system32\SSMS.EXE
G:\WINDOWS\system32\LSSAS.EXE
D:\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btbroadbandstart.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\Run: [Microsoftvirus] sysoverload.exe
O4 - HKLM\..\RunServices: [Windows Run] WinRun.exe
O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\RunServices: [Win32 USB2 service] winsound1.exe
O4 - HKLM\..\RunServices: [Windows OEM Tool] wnres.exe
O4 - HKLM\..\RunServices: [Microsoftvirus] sysoverload.exe
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoftvirus] sysoverload.exe
O4 - Startup: Shortcut to mirc.lnk = C:\Program Files\mIRC\mirc.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095509501766
O17 - HKLM\System\CCS\Services\Tcpip\..\{44790770-CEC5-47E8-8A52-C22BA10E4688}: NameServer = 194.74.65.69 194.72.9.38

Back to top
View users profile Send private message
Flrman1

Security Expert
Microsoft MVP

Joined: Mar 15, 2004
Posts: 1092
Location: North Carolina
MVP Premium Security Experts

PostPosted: Fri Sep 24, 2004 5:26 pm    Post subject:
Reply with quote

Hi DDS

Welcome to CC! Smile

Run Hijack This again and put a check by these. Close ALL windows except HijackThis and click "Fix checked"

O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe

O4 - HKLM\..\Run: [Microsoftvirus] sysoverload.exe

O4 - HKLM\..\RunServices: [Windows Run] WinRun.exe

O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe

O4 - HKLM\..\RunServices: [Win32 USB2 service] winsound1.exe

O4 - HKLM\..\RunServices: [Windows OEM Tool] wnres.exe

O4 - HKLM\..\RunServices: [Microsoftvirus] sysoverload.exe

O4 - HKCU\..\Run: [Microsoftvirus] sysoverload.exe


Restart to safe mode.

How to start your computer in safe mode

Because XP will not always show you hidden files and folders by default, Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"

Next click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"

Now find and delete these files:

G:\WINDOWS\system32\winsysi.exe
G:\WINDOWS\system32\WinRun.exe
G:\WINDOWS\system32\sysoverload.exe
G:\WINDOWS\system32\wnres.exe
G:\WINDOWS\system32\SSMS.EXE -----> (DO Not delete smss.exe)
G:\WINDOWS\system32\LSSAS.EXE -----> (DO Not delete LSASS.EXE)
G:\WINDOWS\system32\service.exe -----> (DO Not delete services.exe)
G:\WINDOWS\system32\csrs.exe -----> (Do Not delete csrss.exe)

Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.

Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.


Empty the Recycle Bin


Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer.

When you are sure you are clean turn it back on and create a restore point.


Go here and do an online virus scan.

Be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the exact file name and file location so you can delete it yourself.


IMPORTANT!: I highly recommend that you go to Windows update and install all "Critical Updates and Service Packs" except for Service Pack 2 ASAP!. This will patch numerous security holes in IE and Windows. Many baddies get on your machine by taking advantage of these vulnerabilities. As your machine stands now it is wide open to attack from all sorts of nasties. You need to get these updates IMMEDITELY!

Note: At this time I cannot and do not recommend that you install Service Pack 2. See here for more info:

http://support.microsoft.com/default.aspx?scid=kb;en-us;884130

And here:

http://support.microsoft.com/default.aspx?kbid=842242

And here:

http://support.microsoft.com/default.aspx?scid=kb;en-us;878474



Last edited by Flrman1 on Fri Sep 24, 2004 5:34 pm, edited 3 times in total
Back to top
View users profile Send private message
Flrman1

Security Expert
Microsoft MVP

Joined: Mar 15, 2004
Posts: 1092
Location: North Carolina
MVP Premium Security Experts

PostPosted: Fri Sep 24, 2004 5:28 pm    Post subject:
Reply with quote

A new version of Hijack This has been released so get rid of the old one and Click here to download the new one, come back here and post the log from it after you have done the above,

Back to top
View users profile Send private message
DDS

Cadet
Cadet


Joined: Sep 24, 2004
Posts: 9
Location: USA

PostPosted: Fri Sep 24, 2004 6:36 pm    Post subject:
Reply with quote

Thank you for the quick responses.. here is the second log using the updated version:

Code:

Logfile of HijackThis v1.98.2
Scan saved at 19:46:43, on 24/09/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetLimiter\NetLimiter.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\mIRC\mirc.exe
G:\WINDOWS\system32\SSMS.EXE
C:\mysql\bin\mysqld-nt.exe
G:\WINDOWS\system32\LSSAS.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\MsPMSPSv.exe
G:\Program Files\Symantec\LiveUpdate\LUALL.EXE
G:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\ABC\ABC.exe
D:\Downloads\HijackThis.exe
D:\Downloads\hijackthis-1.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Connect to BT Broadband.lnk = G:\Program Files\BT Voyager 105 ADSL Modem\BT Broadband.exe
O4 - Startup: Shortcut to mirc.lnk = C:\Program Files\mIRC\mirc.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096048970216
O17 - HKLM\System\CCS\Services\Tcpip\..\{44790770-CEC5-47E8-8A52-C22BA10E4688}: NameServer = 194.74.65.69 194.72.9.38



I think it looks clean now?

Back to top
View users profile Send private message
Flrman1

Security Expert
Microsoft MVP

Joined: Mar 15, 2004
Posts: 1092
Location: North Carolina
MVP Premium Security Experts

PostPosted: Fri Sep 24, 2004 9:41 pm    Post subject:
Reply with quote

Boot to safe mode and delete these files:

G:\WINDOWS\system32\SSMS.EXE -----> (DO Not delete smss.exe)
G:\WINDOWS\system32\LSSAS.EXE -----> (DO Not delete LSASS.EXE)

Update your virus definitions and do a full system scan.

Back to top
View users profile Send private message
DDS

Cadet
Cadet


Joined: Sep 24, 2004
Posts: 9
Location: USA

PostPosted: Fri Sep 24, 2004 10:42 pm    Post subject:
Reply with quote

Hey i've done what you have ask and here is the current log.. Hopefully now i can say im cleaned?

Code:

Logfile of HijackThis v1.98.2
Scan saved at 23:48:46, on 24/09/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\system32\spoolsv.exe
C:\mysql\bin\mysqld-nt.exe
G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetLimiter\NetLimiter.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\mIRC\mirc.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\MsPMSPSv.exe
G:\WINDOWS\System32\wuauclt.exe
D:\Downloads\hijackthis-1.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Connect to BT Broadband.lnk = G:\Program Files\BT Voyager 105 ADSL Modem\BT Broadband.exe
O4 - Startup: Shortcut to mirc.lnk = C:\Program Files\mIRC\mirc.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096048970216
O17 - HKLM\System\CCS\Services\Tcpip\..\{44790770-CEC5-47E8-8A52-C22BA10E4688}: NameServer = 194.74.65.69 194.72.9.38

Back to top
View users profile Send private message
Flrman1

Security Expert
Microsoft MVP

Joined: Mar 15, 2004
Posts: 1092
Location: North Carolina
MVP Premium Security Experts

PostPosted: Fri Sep 24, 2004 11:06 pm    Post subject:
Reply with quote

Clean! Thumbs Up

Back to top
View users profile Send private message
DDS

Cadet
Cadet


Joined: Sep 24, 2004
Posts: 9
Location: USA

PostPosted: Fri Sep 24, 2004 11:25 pm    Post subject:
Reply with quote

That was the best response i've ever seen.. you really do yourselfs proud, thanks guys.

<3

You've earnt yourself a bookmark!

Back to top
View users profile Send private message
Flrman1

Security Expert
Microsoft MVP

Joined: Mar 15, 2004
Posts: 1092
Location: North Carolina
MVP Premium Security Experts

PostPosted: Fri Sep 24, 2004 11:39 pm    Post subject:
Reply with quote

You're Welcome! Smile

Back to top
View users profile Send private message
lilliebet

General
General
Premium Member

Joined: Dec 03, 2003
Posts: 7014

Premium Team F@H

PostPosted: Sat Sep 25, 2004 7:12 am    Post subject:
Reply with quote

Glad we were able to help. Smile

NOTE: This thread is now closed. Should you need it reopened, please PM a mod.
Everyone else having a similar issue, please launch a new topic for yourselves.

To reduce the chances of future Spyware/Hijacking problems, please follow the suggestions here: CastleCops Link/t7736-So_how_did_I_get_infected_in_the_first_place.html


_________________
Lilliebet...another point of view
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   This topic is locked you cannot edit posts or make replies       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer