Avast Online Scanner Messages

Hi Everyone, I hope someone can hrlp me out here.

I keep getting this message poping up:

http://85.255.117.133/users/smart/web/files/encodex.jpg contains sample of 'Win32:Agent-UI [trj]"!

http://85.255.115.187/users/fill/web/images/logo_big.jpg contains sample of “Win32:Small-EK[Trj]”!

http://85.255.115.187/users/fill/web/images/sphlp32.jpg contains sample of “Win32:Adan-094[Adw]”!

http://85.255.115.187/users/fill/web/images/logo_big.jpg contains sample of “Win32:Adan-078[Adw]”!

I just ran a highjack log file, but it is too long to post. Here’s as much as I could get posted.

Logfile of HijackThis v1.99.1
Scan saved at 6:39:20 PM, on 4/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\FlashGet\flashget.exe
C:\Documents and Settings\Customers\Local Settings\Temporary Internet Files\Content.IE5\G5OGNRPW\aswclnr[1].exe
C:\Documents and Settings\Customers\Local Settings\Temporary Internet Files\Content.IE5\G5OGNRPW\aswclnr[1].tmp
C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mail.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.we1.attbb.net:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.we1.attbb.net;
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {160884EE-B531-4C0B-9A44-5B2569F14C31} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {194449FD-0129-4679-8E26-67687C13429F} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {2405B227-1B71-4814-8761-39EC689380CF} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {432AF96D-0B6A-4F84-929B-37794934B10E} - C:\WINDOWS\System32\mskl.dll (file missing)
O2 - BHO: (no name) - {4E1B1B2F-4CA6-4AB9-8F41-7996D2F93ECC} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {5A99F3FB-7119-45A3-B879-EA0AEED39ACB} - C:\WINDOWS\ICLEAR~1\ICLEAR~1.dll (file missing)
O2 - BHO: (no name) - {69A7CC2C-59FF-4F0D-B211-9F09591637CD} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {69F528E4-D162-4BD8-A812-F382FDD99616} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {82D9249B-FE4F-4FA4-9977-B5EFAC7821F8} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {9CD5B164-4EC3-48FA-A661-9953AC363C2F} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {9EA3548B-4C6A-419D-B4AB-69BA73984C2F} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: (no name) - {A5551E54-1D00-4E10-BDEC-91CC1834F5A5} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: (no name) - {A706CDC5-9AE8-40B5-8FAC-301D1DE77AB9} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {DE6731CD-D447-43C6-9FA3-030786FFC62C} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O2 - BHO: (no name) - {F5B0E7D8-E7E6-415E-B3FB-AB1E8A918EB4} - C:\Program Files\ClearSearch\ClearSearch.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

Any help would be fantastic!

Thanks,
miss ammo

Can you post a screenshot of the message or not?

Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.

I did a boot scan twice and it didn’t catch anything.

I’m not sure but this seems WebShield warning… you should have being receiving a virus message (window) either…
You’re using FlashGet. Avast detects some files of it as “Win32:Adan-078[Adw]” infected indeed… FlashGet is an adware (and a lot of scanners consider the payed version as adware too).

:slight_smile: Hi Ammoyeah :

  You do NOT seem to have any antiSPYWARE program(s)
  on your computer and it appears you have a spyware
  problem ; I recommend you ask the Experts on the forums
  at www.landzdown.com .

  P.S. In addition to the "suspect" Flashget, unless you use
  AOL as your ISP, "Viewpoint Manager" should be removed.

The second half of your HjackThis! log is crucial. Can you copy and paste just the missing information?

If this is happening and you are not actually browsing that website you may well have a trojan on your system that is trying to make these connections to download more malware.

If you do a forum search for ‘users/fill/web’ without the quotes you find other posts like this as I remember something like this recently.

Hi FreewheelinFrank,

Here is the rest of the Hijack:

O4 - HKLM..\Run: [VTTimer] VTTimer.exe
O4 - HKLM..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM..\Run: [QuickTime Task] “C:\Program Files\QuickTime\qttask.exe” -atboottime
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM..\Run: [TkBellExe] “C:\Program Files\Common Files\Real\Update_OB\realsched.exe” -osboot
O4 - HKLM..\Run: [hgqhp.exe] C:\WINDOWS\system32\hgqhp.exe
O4 - HKCU..\Run: [PopUpStopperFreeEdition] “C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe”
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [WareOut] “C:\Program Files\WareOut\WareOut.exe”
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Free WebSite Tools.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Sothink SWF Decompiler - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: GloPhone - {C9B8ABB6-1CC3-4957-9CA3-053036B2EE3A} - C:\Program Files\Voiceglo\Glophone\glophone.exe (file missing)
O9 - Extra button: (no name) - {C9B8ABB6-1CC3-4957-9CA3-053036B2EE3A}} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra ‘Tools’ menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: SWFDecompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra ‘Tools’ menuitem: Sothink SWF Decompiler - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\SourceTec\Sothink SWF Decompiler\InternetExplorer.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.search-soft.net
O16 - DPF: {F9043C85-F6F2-101A-A3C9-08002B2F49FB} (Microsoft Common Dialog Control, version 6.0) - file://C:\Program Files\OpenCube\Visual Infinite Menus\comdlg32.cab
O17 - HKLM\System\CCS\Services\Tcpip..{54A10E08-B3F2-4EA0-9494-9336FBEABCA9}: NameServer = 85.255.116.134,85.255.112.210
O17 - HKLM\System\CCS\Services\Tcpip..{877C6229-7A21-4FD7-964F-145766E51F6E}: NameServer = 85.255.116.134,85.255.112.210
O17 - HKLM\System\CCS\Services\Tcpip..{94EF503B-F753-4E2D-9330-7AEFA757FA39}: NameServer = 85.255.116.134,85.255.112.210
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Thanks,
miss ammo

Oops! Missed part two here!

Signs of a Trojan in the log:

http://hijackthis.de/logfiles/44cb551ca809125673b5e9a693d17b06.html

http://www.sophos.com/virusinfo/analyses/trojdnschank.html

And no firewall detected, but I guess ammoyeah has gone. Sorry.

Also hgqhp.exe is a trojan see here http://www.securitystronghold.com/gates/spyware-adware-solutions/hgqhp.exe_hgqhp.exe_solution.htm

Possible solution here third post http://pcpitstop.invisionzone.com/lofiversion/index.php/t107809.html

That’s the same beastie as the Sophos write-up. :wink:

i got the same “thing” around…

Logfile of HijackThis v1.99.1
Scan saved at 8:37:26 PM, on 7/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\TM Net\tmnet streamyx dialer\fts.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\TM Net\Diagnostic Tool\tmnet connect.exe
C:\Program Files\TM Net\tmnet streamyx dialer\fwportal.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\baj\hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tm.net.my/
R3 - URLSearchHook: (no name) - {5E9787B9-8E07-7D9E-3F1A-07AF0F9843BC} - EXE32EXE.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [%FP%TM Net fts.exe] “C:\Program Files\TM Net\tmnet streamyx dialer\fts.exe”
O4 - HKLM..\Run: [blrsa.exe] C:\WINDOWS\system32\blrsa.exe
O4 - HKLM..\Run: [tkxgz.exe] C:\WINDOWS\system32\tkxgz.exe
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip..{0EDFD05B-7C15-4A2D-817C-DA300E5195BA}: NameServer = 85.255.115.6,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip..{F2430DF8-E4F8-4CFE-8910-28B4ACDD5792}: NameServer = 202.188.0.133 202.188.1.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.6 85.255.112.20
O17 - HKLM\System\CS1\Services\Tcpip..{0EDFD05B-7C15-4A2D-817C-DA300E5195BA}: NameServer = 85.255.115.6,85.255.112.20
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.6 85.255.112.20
O17 - HKLM\System\CS2\Services\Tcpip..{0EDFD05B-7C15-4A2D-817C-DA300E5195BA}: NameServer = 85.255.115.6,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.6 85.255.112.20
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Tango Service (TangoService) - Unknown owner - C:\Program Files\Efficient Networks\Tango Manager\app\TangoService.exe

The following lines could be a virus:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tm.net.my/
O4 - HKLM..\Run: [%FP%TM Net fts.exe] “C:\Program Files\TM Net\tmnet streamyx dialer\fts.exe”
O4 - HKLM..\Run: [blrsa.exe] C:\WINDOWS\system32\blrsa.exe
O4 - HKLM..\Run: [tkxgz.exe] C:\WINDOWS\system32\tkxgz.exe
O17 - HKLM\System\CCS\Services\Tcpip..{0EDFD05B-7C15-4A2D-817C-DA300E5195BA}: NameServer = 85.255.115.6,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip..{F2430DF8-E4F8-4CFE-8910-28B4ACDD5792}: NameServer = 202.188.0.133 202.188.1.5
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.6 85.255.112.20
O17 - HKLM\System\CS1\Services\Tcpip..{0EDFD05B-7C15-4A2D-817C-DA300E5195BA}: NameServer = 85.255.115.6,85.255.112.20
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.6 85.255.112.20
O17 - HKLM\System\CS2\Services\Tcpip..{0EDFD05B-7C15-4A2D-817C-DA300E5195BA}: NameServer = 85.255.115.6,85.255.112.20
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.6 85.255.112.20

ALso try to run Security Task Manager (http://www.snapfiles.com/get/securitytask.html). Security Task Manager shows a Spyware Rating for the running processes. It is not because a file has a high spyware rating that it is a virus. Most of the processes with a high spyware rating are not virusses. You should look for files that have a high spyware rating in Security Task Manager and that are also started in the hyjack.log. Also do a search on google.com. If you don’t find anything about a file with a high spyware rating on google.com then it should be a virus.

In Security Task Manager look for the following processes :
C:\Program Files\TM Net\tmnet streamyx dialer\fts.exe
C:\Program Files\TM Net\tmnet streamyx dialer\fwportal.exe
C:\Program Files\TM Net\Diagnostic Tool\tmnet connect.exe
C:\WINDOWS\system32\blrsa.exe
C:\WINDOWS\system32\tkxgz.exe

To remove them you should rightclick mouse button. Choose menu option “remove…”. Choose menu option “move to quarantine”. And maybe you will need to reboot your PC in safe mode (=press F8 during reboot).

You could also look at the properties from the files :
C:\Program Files\TM Net\tmnet streamyx dialer\fts.exe
C:\Program Files\TM Net\tmnet streamyx dialer\fwportal.exe
C:\Program Files\TM Net\Diagnostic Tool\tmnet connect.exe
C:\WINDOWS\system32\blrsa.exe
C:\WINDOWS\system32\tkxgz.exe

If you find any keyshortcuts in the properties of these files, then disable the keyshorcuts. Because anytime you use these keyshorcuts the virus will be started again.

It could be that after you kill the process and remove the lines from hyjack.log that the virus process is started again and the virus add again the virus lines to hyjack.log. So when you think you get rid of the virus, you should scan again with hyjackthis and do a refresh with Security Task Manager to see if the processes are really deleted.

You should also check if the following files/folders are correctly removed (don’t forget to enable “show system/hidden files” in your file explorer) :
C:\Program Files\TM Net
C:\WINDOWS\system32\blrsa.exe
C:\WINDOWS\system32\tkxgz.exe

@ ridzal
The common factor for most of this malware is in the system folders and you (read the malware) need permissions/admin rights to do this.

Whilst browsing or collecting email, etc. if you get infected then the malware by default inherits the same permissions that you have for your user account. So if the user account has administrator rights, the malware has administrator rights and can reap havoc. With limited rights the malware can’t put files in the system folders, create registry entries, etc. This greatly reduces the potential harm that can be done by an undetected or first day virus, etc.

Check out the link to DropMyRights (in my signature below) - Browsing the Web and Reading E-mail Safely as an Administrator. This obviously applies to those NT based OSes that have administrator settings, winNT, win2k, winXP.

The IP address in the 017 entries could be your ISP (see quote below) or related to it so you would need to confirm this, if you fix these entries and can’t get internet access, that is likely to be the reason, so you would need to restore them in HJT.

inetnum: 85.255.112.0 - 85.255.127.255 netname: inhoster descr: Inhoster hosting company descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine

You don’t appear to have an active firewall ?
For an on-line analysis of you log (Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.) http://hijackthis.de/logfiles/8747e12149db5c079b0f9a97d7d43dcc.html The ones mentioned by ‘ericzutter’ are there as are a number of other Possibly Nasty and Unknown entries, which if you don’t recognise them (e.g. you installed them) check them out, google the file name, etc.

If you haven’t already got this software (freeware), download, install, update and run it.

  1. Ad-Aware
  2. Spybot Search and Destroy
  3. Spywareblaster Don’t install this until you are clean.

Another interesting tool is Sandboxie (http://www.sandboxie.com/). You could compare it to the tool DropMyRights, with the difference that DropMyRights will strip apps from certain rights and running apps with Sandboxie will deny malware the chance to see the real registry and file system.

For example, your run your web browser with Sandboxie. You download a virus, install it on your computer, the virus changes your registry, infect your system files. You close your web browser and you have a clean system. Why, because Sandboxie has done all these modifications to a fake registry and a fake file system. The fake registery and fake file system are removed after closing your web browser leaving you with a clean system.

Not wanting to take this Topic off Topic, perhaps creating a new topic in the General forum on Sandboxie.
What are the overheads of using sandboxie resources, etc. ?

I certainly like the sound of it and will have a look at the web site. However my concern is being a dial-up user I start my browser of choice at the start of the day and leave it on all day. In closing the browser from sandboxie do you also lose the browser cache, favourites, etc. I would assume so ?

If that were to be the case that would slow subsequent loading of pages that would otherwise be in the cache.

I created a new topic in the General forum on Sandboxie. (http://forum.avast.com/index.php?topic=22589.msg186959#msg186959)

I answered to your questions in the new topic.

Thanks and a belated welcome to the forums.