Link to home
Start Free TrialLog in
Avatar of oceanbeach
oceanbeach

asked on

Having trouble removing some threats

Hello Experts.

I am having trouble removing some viruses & Adware.  I will upload a HJT log to ee-stuff.com.

Any help would be greatly appreciated!  Thanks!

oceanbeach
ASKER CERTIFIED SOLUTION
Avatar of and235100
and235100
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of oceanbeach
oceanbeach

ASKER

For other people's ease of use:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:24:33 AM, on 11/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Compaq_Administrator\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: {8c9ebd99-203b-a2c8-a174-529753800e8e} - {e8e00835-7925-471a-8c2a-b30299dbe9c8} - C:\WINDOWS\system32\ojdgcnqi.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [1457c86f] rundll32.exe "C:\WINDOWS\system32\ehgulspw.dll",b
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O20 - Winlogon Notify: iifcbbc - C:\WINDOWS\SYSTEM32\iifcbbc.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe

--
End of file - 7441 bytes
O4 - HKLM\..\Run: [1457c86f] rundll32.exe "C:\WINDOWS\system32\ehgulspw.dll",b
This may be suspicious. Other than that - apart from a lot of unnecessary HP services - I can't see anything else that is really harmful - someone else might though.

What problems are you experiencing?
Apologies -

O20 - Winlogon Notify: iifcbbc - C:\WINDOWS\SYSTEM32\iifcbbc.dll

may be suspect too.
Online scanners sometimes just make you aware of the malware located in certain files.
The suspect browser objects need to be deleted - SuperAntiSpyware will do this for you.
The skipped files look like logs and txt files in use by the system - rather than suspected malware.

What did the SuperAntiSpyware scan come back with?
infected: Trojan.Win32.BHO.re
Infected: Trojan.Win32.BHO.rg

HP and Compaq files infected as well.

BHO: (very little on symantec) -- http://www.symantec.com/security_response/writeup.jsp?docid=2007-082301-4219-99&tabid=2
Hi Experts,

Sorry, I missed this..."What problems are you experiencing?"
-mostly popups

I have removed many threats already, but these last ones are being difficult.  The kaspersky scan is from yesterday.

I have ran  SuperAntispyware and uploaded the log...

https://filedb.experts-exchange.com/incoming/ee-stuff/5728-kaspersky_111907-1130.ziphttps://filedb.experts-exchange.com/incoming/ee-stuff/5729-ewido-report_112007-0740.zip
https://filedb.experts-exchange.com/incoming/ee-stuff/5730-hijackthis_112007-0756.zip
https://filedb.experts-exchange.com/incoming/ee-stuff/5715-SUPERAntiSpyware.txt
https://filedb.experts-exchange.com/incoming/ee-stuff/5708-hijackthis.zip
https://filedb.experts-exchange.com/incoming/ee-stuff/5709-kaspersky.zip


After rebooting, I received this error:
-"Error loading C:\Windows\system32\ehgulspw.dll"

I removed the following registry value (and the error message did not reappear):
-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\run\1457c86f
Value: rundll32.exe "C:\WINDOWS\system32\ehgulspw.dll",b

I will run a full online scan at HouseCall right now.

Thanks!

oceanbeach
What about
O2 - BHO: {8c9ebd99-203b-a2c8-a174-529753800e8e} - {e8e00835-7925-471a-8c2a-b30299dbe9c8} - C:\WINDOWS\system32\ojdgcnqi.dll
?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hello Experts,

Somehow, the online scan at HouseCall failed.  I will run an additional scan.

Should I remove the infected dll files & the associated registry entries?  Is there any place to find out if a dll file is legitimate or not?

-OB

Just post the ones you don;t know about - and someone can assist...
Hi Experts,

I received an indication from HouseCall that 'Bifrose' was detected.  This does not seem to be reported by any other scan I have ran.  I was not able to determine what file(s) may have been infected.  Any ideas on how I can confirm this infection?  Is it a false positive?

The online scan at HouseCall has been problematic.  I would try to run another scan if I thought it would help, but I keep having trouble with it.

Thanks!

oceanbeach
SOLUTION
Avatar of rpggamergirl
rpggamergirl
Flag of Australia image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hello EE,

Sorry for the delay.  This has taken a little longer than I had hoped, and I just had to get some other work done yesterday.

I have uploaded:
-kaspersky log (from yesterday)
-ewido log
-HJT log

"Did SUPERAntispyware removed all vundof files detected?"
-I am not sure.  It did remove many infected files, but I Spybot found another infection today.  Also, a Spyware Doctor scan after SuperAntiSpyware seemed to come up with several of the same items that SuperAntiSpyware indicated were removed.  An additional AntiSpyware scan after the Spyware Doctor scan gave a clean result.

"You can try running another Kaspersky scan..."
-I have not done this yet, but the most recent scan looks OK, do you agree?  I could rerun another one.

"Does housecall gives you a log?"
-I was not able to obtain one.  The first 2 scans I did locked up the browser.  The third one completed and I was able to see the results), but frooze the browser again shortly there after.  I did run a Biut Defender scan yesterday that came back clean.

Thanks again for everyones help!

-OB
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hello Experts,

I apologize for not posting sooner.  I have solved my problem.  I wish I could say exactly what I did, but I had to do quite a bit to clean this machine, too much to say in detail.

Thanks!

-OB
Experts,

This was tough.  I actually fixed the problem on my own.  However, the most helpful suggestion was to run SuperAntiSpyware.  All other efforts were helpful as well, but I had to do a lot of other work to clean this machine.

Thanks to all that helped out.  I hope everyone agrees to the point split (it was the best I could do).  Let me know if anyone thinks this seems unfair.  I will be more than happy to rereview anything here.

Thanks again!

-OB
No problem - apologies that the assistance wasn't spot on - malware-related problems are sometimes exceptionally hard to clean off permanently (after all that is what they are designed for!)
Thanks in any case.
Glad to know you've resolved it, sorry you had to do a lot more on your own.
In similar cases like this, you also have the option to ask for a refund of your points.

Thank you for awarding the points! very generous of you.

Good luck, :)