| View previous topic :: View next topic |
| Author |
Message |
DDS
Cadet

 Joined: Sep 24, 2004 Posts: 9 Location: USA
|
Posted: Fri Sep 24, 2004 4:58 pm Post subject: Hi-jack Log help |
|
|
Hello guys pretty sure i have a virus as sysoverload.exe seems dodgy but would ask for help before i delete also is \RunServices: [Win32 USB2 service] winsound1.exe ok? and O4 - HKLM\..\RunServices: [Windows OEM Tool] wnres.exe
Anyway here is the log, thanks for any help you provide:
| Code: | Logfile of HijackThis v1.97.7
Scan saved at 18:06:30, on 24/09/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\logonui.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
G:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NetLimiter\NetLimiter.exe
C:\Program Files\QuickTime\qttask.exe
C:\mysql\bin\mysqld-nt.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\mIRC\mirc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Ad-aware 6\Ad-watch.exe
G:\WINDOWS\system32\service.exe
G:\WINDOWS\system32\csrs.exe
G:\WINDOWS\system32\SSMS.EXE
G:\WINDOWS\system32\LSSAS.EXE
D:\Downloads\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btbroadbandstart.com/
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\Run: [Microsoftvirus] sysoverload.exe
O4 - HKLM\..\RunServices: [Windows Run] WinRun.exe
O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\RunServices: [Win32 USB2 service] winsound1.exe
O4 - HKLM\..\RunServices: [Windows OEM Tool] wnres.exe
O4 - HKLM\..\RunServices: [Microsoftvirus] sysoverload.exe
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Microsoftvirus] sysoverload.exe
O4 - Startup: Shortcut to mirc.lnk = C:\Program Files\mIRC\mirc.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1095509501766
O17 - HKLM\System\CCS\Services\Tcpip\..\{44790770-CEC5-47E8-8A52-C22BA10E4688}: NameServer = 194.74.65.69 194.72.9.38
|
|
|
| Back to top |
|
 |
Flrman1
Security Expert Microsoft MVP
 Joined: Mar 15, 2004 Posts: 1092 Location: North Carolina
|
Posted: Fri Sep 24, 2004 5:26 pm Post subject: |
|
|
Hi DDS
Welcome to CC!
Run Hijack This again and put a check by these. Close ALL windows except HijackThis and click "Fix checked"
O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\Run: [Microsoftvirus] sysoverload.exe
O4 - HKLM\..\RunServices: [Windows Run] WinRun.exe
O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\RunServices: [Win32 USB2 service] winsound1.exe
O4 - HKLM\..\RunServices: [Windows OEM Tool] wnres.exe
O4 - HKLM\..\RunServices: [Microsoftvirus] sysoverload.exe
O4 - HKCU\..\Run: [Microsoftvirus] sysoverload.exe
Restart to safe mode.
How to start your computer in safe mode
Because XP will not always show you hidden files and folders by default, Go to Start > Search and under "More advanced search options".
Make sure there is a check by "Search System Folders" and "Search hidden files and folders" and "Search system subfolders"
Next click on My Computer. Go to Tools > Folder Options. Click on the View tab and make sure that "Show hidden files and folders" is checked. Also uncheck "Hide protected operating system files" and "Hide extensions for known file types" . Now click "Apply to all folders"
Click "Apply" then "OK"
Now find and delete these files:
G:\WINDOWS\system32\winsysi.exe
G:\WINDOWS\system32\WinRun.exe
G:\WINDOWS\system32\sysoverload.exe
G:\WINDOWS\system32\wnres.exe
G:\WINDOWS\system32\SSMS.EXE -----> (DO Not delete smss.exe)
G:\WINDOWS\system32\LSSAS.EXE -----> (DO Not delete LSASS.EXE)
G:\WINDOWS\system32\service.exe -----> (DO Not delete services.exe)
G:\WINDOWS\system32\csrs.exe -----> (Do Not delete csrss.exe)
Also in safe mode navigate to the C:\Windows\Temp folder. Open the Temp folder and go to Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Go to Start > Run and type %temp% in the Run box. The Temp folder will open. Click Edit > Select All then Edit > Delete to delete the entire contents of the Temp folder.
Finally go to Control Panel > Internet Options. On the General tab under "Temporary Internet Files" Click "Delete Files". Put a check by "Delete Offline Content" and click OK. Click on the Programs tab then click the "Reset Web Settings" button. Click Apply then OK.
Empty the Recycle Bin
Turn off System Restore:
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer.
When you are sure you are clean turn it back on and create a restore point.
Go here and do an online virus scan.
Be sure and put a check in the box by "Auto Clean" before you do the scan. If it finds anything that it cannot clean have it delete it or make a note of the exact file name and file location so you can delete it yourself.
IMPORTANT!: I highly recommend that you go to Windows update and install all "Critical Updates and Service Packs" except for Service Pack 2 ASAP!. This will patch numerous security holes in IE and Windows. Many baddies get on your machine by taking advantage of these vulnerabilities. As your machine stands now it is wide open to attack from all sorts of nasties. You need to get these updates IMMEDITELY!
Note: At this time I cannot and do not recommend that you install Service Pack 2. See here for more info:
http://support.microsoft.com/default.aspx?scid=kb;en-us;884130
And here:
http://support.microsoft.com/default.aspx?kbid=842242
And here:
http://support.microsoft.com/default.aspx?scid=kb;en-us;878474
Last edited by Flrman1 on Fri Sep 24, 2004 5:34 pm, edited 3 times in total |
|
| Back to top |
|
 |
Flrman1
Security Expert Microsoft MVP
 Joined: Mar 15, 2004 Posts: 1092 Location: North Carolina
|
Posted: Fri Sep 24, 2004 5:28 pm Post subject: |
|
|
A new version of Hijack This has been released so get rid of the old one and Click here to download the new one, come back here and post the log from it after you have done the above,
|
|
| Back to top |
|
 |
DDS
Cadet

 Joined: Sep 24, 2004 Posts: 9 Location: USA
|
Posted: Fri Sep 24, 2004 6:36 pm Post subject: |
|
|
Thank you for the quick responses.. here is the second log using the updated version:
| Code: |
Logfile of HijackThis v1.98.2
Scan saved at 19:46:43, on 24/09/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetLimiter\NetLimiter.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\mIRC\mirc.exe
G:\WINDOWS\system32\SSMS.EXE
C:\mysql\bin\mysqld-nt.exe
G:\WINDOWS\system32\LSSAS.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\MsPMSPSv.exe
G:\Program Files\Symantec\LiveUpdate\LUALL.EXE
G:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\ABC\ABC.exe
D:\Downloads\HijackThis.exe
D:\Downloads\hijackthis-1.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Connect to BT Broadband.lnk = G:\Program Files\BT Voyager 105 ADSL Modem\BT Broadband.exe
O4 - Startup: Shortcut to mirc.lnk = C:\Program Files\mIRC\mirc.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096048970216
O17 - HKLM\System\CCS\Services\Tcpip\..\{44790770-CEC5-47E8-8A52-C22BA10E4688}: NameServer = 194.74.65.69 194.72.9.38
|
I think it looks clean now?
|
|
| Back to top |
|
 |
Flrman1
Security Expert Microsoft MVP
 Joined: Mar 15, 2004 Posts: 1092 Location: North Carolina
|
Posted: Fri Sep 24, 2004 9:41 pm Post subject: |
|
|
Boot to safe mode and delete these files:
G:\WINDOWS\system32\SSMS.EXE -----> (DO Not delete smss.exe)
G:\WINDOWS\system32\LSSAS.EXE -----> (DO Not delete LSASS.EXE)
Update your virus definitions and do a full system scan.
|
|
| Back to top |
|
 |
DDS
Cadet

 Joined: Sep 24, 2004 Posts: 9 Location: USA
|
Posted: Fri Sep 24, 2004 10:42 pm Post subject: |
|
|
Hey i've done what you have ask and here is the current log.. Hopefully now i can say im cleaned?
| Code: |
Logfile of HijackThis v1.98.2
Scan saved at 23:48:46, on 24/09/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\Explorer.EXE
G:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
G:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
G:\WINDOWS\system32\spoolsv.exe
C:\mysql\bin\mysqld-nt.exe
G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
G:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetLimiter\NetLimiter.exe
G:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\mIRC\mirc.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\MsPMSPSv.exe
G:\WINDOWS\System32\wuauclt.exe
D:\Downloads\hijackthis-1.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [CTSysVol] G:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [SBDrvDet] G:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "G:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NetLimiter] C:\Program Files\NetLimiter\NetLimiter.exe /s
O4 - HKCU\..\Run: [MsnMsgr] "G:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: Connect to BT Broadband.lnk = G:\Program Files\BT Voyager 105 ADSL Modem\BT Broadband.exe
O4 - Startup: Shortcut to mirc.lnk = C:\Program Files\mIRC\mirc.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1096048970216
O17 - HKLM\System\CCS\Services\Tcpip\..\{44790770-CEC5-47E8-8A52-C22BA10E4688}: NameServer = 194.74.65.69 194.72.9.38
|
|
|
| Back to top |
|
 |
Flrman1
Security Expert Microsoft MVP
 Joined: Mar 15, 2004 Posts: 1092 Location: North Carolina
|
Posted: Fri Sep 24, 2004 11:06 pm Post subject: |
|
|
Clean! 
|
|
| Back to top |
|
 |
DDS
Cadet

 Joined: Sep 24, 2004 Posts: 9 Location: USA
|
Posted: Fri Sep 24, 2004 11:25 pm Post subject: |
|
|
That was the best response i've ever seen.. you really do yourselfs proud, thanks guys.
<3
You've earnt yourself a bookmark!
|
|
| Back to top |
|
 |
Flrman1
Security Expert Microsoft MVP
 Joined: Mar 15, 2004 Posts: 1092 Location: North Carolina
|
Posted: Fri Sep 24, 2004 11:39 pm Post subject: |
|
|
You're Welcome! 
|
|
| Back to top |
|
 |
lilliebet
General
 Premium Member
 Joined: Dec 03, 2003 Posts: 7014
|
|
| Back to top |
|
 |
|
|