View Single Post

  #2  
Old 03-12-2005, 04:52 PM
Cache's Avatar
Cache Offline
ST&T Secret Police
 
Join Date: Jun 2004
Location: UK
Posts: 616
OK, first im going to ask you to put the Spyware aside for a while as you have more nasty items in your log.

You seem to be infected with a variant of the W32/RBOT-PL worm, either RBOT-PL or RBOT-FP, and maybe also Dloader-HW and W32.HLLW.Slideshow

Please update your antivirus and run a full system scan. After that run the below online scans:

http://housecall.trendmicro.com/
and
http://www.windowsecurity.com/trojanscan/

Next download CWShreder from the link below:

http://www.intermute.com/spysubtract..._download.html

Next update CWShreder, Spybot and AD-aware, also download VX2 cleaner plugin for AD-aware from the link below and install it:

http://www.lavasoftusa.com/software/...2cleaner.shtml

Next run a full scan with all three programs (CWShreder, AD-aware and Spybot), aslo make sure you run a scan with the VX2 plugin with AD-aware.

When you have done all the above, run HJT again and post a new log.

Just so you know, the thing that are either known nasties or at least very suspicious in your log are:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - Default URLSearchHook is missing
O2 - BHO: &EliteBar - {28CAEFF3-0F18-4036-B504-51D73BD81ABC} - C:\WINNT\EliteToolBar\EliteToolBar.dll
O2 - BHO: (no name) - {6AA66C12-AB8E-8C50-87EA-830A7279A699} - C:\WINNT\system32\ktffw.dll
O2 - BHO: (no name) - {A381310E-25C7-1586-7EEB-AEE0C9893617} - C:\WINNT\system32\xeqjdgrc.dll
O2 - BHO: (no name) - {B74A3D53-38F5-11B5-5455-02C9A19181BF} - C:\WINNT\system32\vbwtefad
O2 - BHO: (no name) - {D8B09EF3-6298-4041-A329-321EFD14916D} - C:\WINNT\system32\pbursvfy.dll (file missing)
O3 - Toolbar: &EliteBar - {825CF5BD-8862-4430-B771-0C15C5CA8DEF} - C:\WINNT\EliteToolBar\EliteToolBar.dll
O4 - HKLM\..\Run: [2SWZKN82R5K47C] C:\WINNT\system32\RirZr.exe
O4 - HKLM\..\Run: [b3866f0c720b] C:\WINNT\System32\browselc.exe
O4 - HKLM\..\Run: [Dvx] C:\WINNT\System32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [winupdtl] C:\WINNT\system32\winupdt.exe
O4 - HKLM\..\Run: [zvmcmnci] c:\winnt\system32\zvmcmnci.exe
O4 - HKLM\..\Run: [778g3sQ] objmovie.exe
O4 - HKLM\..\Run: [App32dll] C:\winnt\system32\msnavc32.exe lee0105
O4 - HKLM\..\Run: [antiware] C:\winnt\system32\eliteukr32.exe
O4 - HKLM\..\Run: [osigeepm] C:\WINNT\system32\osigeepm.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
O4 - HKCU\..\Run: [MSCVT] C:\Windows\MSCVT.exe
O4 - HKCU\..\Run: [OVCKPY] C:\WINNT\QDUSJ.exe
O4 - HKCU\..\Run: [Ltho] C:\Documents and Settings\Owner\Application Data\dees.exe
O4 - HKCU\..\Run: [Mwakcesm] C:\WINNT\system32\?hkdsk.exe
O4 - HKCU\..\Run: [MwrmRic2h] nv4onf.exe
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {EB623776-492A-42CA-9571-3AA39F58530B} - http://www.alwaysupdatednews.com/install/aun_0033.exe
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINNT\isrvs\mfiltis.dll
O23 - Service: hndlqghhbwfh (vdeqnhnu6) - Unknown owner - C:\WINNT\system32\eeqxaxtv6.exe (file missing)

But I suggest you folow the instructions above and post a new log before you fix anything using HJT if you dont know what your doing.

Last edited by cache : 03-12-2005 at 04:54 PM.
Reply With Quote