Win32:Trojan-gen. {Delphi} Help

Hi

I was wondering if someone could help me, 3 days ago my avast! 4.6 Home warned me about this trojan in the temp folder, i moved it to the chest and erased it. The problem seems to be that every time i restart a session it multiplies itself, avast warned that the memory is affected but after i erase the files it doesn’t give me any warning. I haven’t noticed any diference in the pc’s performance neither annoying pop-ups have showed up, there are some files that seem to be infected too but i can’t move them to the chest (don’t know why):
C:\WINDOWS\system32\Winlog.com[UPX]
C:\WINDOWS\system32\OPE2.exe[UPX]
C:\WINDOWS\system32\DXWINEX.exe[UPX]
I also can’t find this files through a windows search.

Thanks in advance and my apoligies for my rude english :-[

If you have winXP, you can schedule a boot-time scan from within avast.

there are some files that seem to be infected too but i can't move them to the chest (don't know why):
When a file is in use windows protects it, so you can't delet or move it and becayse it is in the windows\system32 folder if you are able to delete it, it is likely to be saved by system restore to a restore point.

Again if you have XP, then use Task Manager and check if you can see the running processes of the above files, you can end the task, then you should be able to delete or move to chest.

Hi

First Disable System Restore

Then as David suggested run a boot time scan with avast set to scan within archives (open avast > Menu (top left hand corner) >boot time scan)

Then post a hijackthis log here: http://members.home.nl/edeijl/download/hijackthis.exe

–lee

Logfile of HijackThis v1.99.1
Scan saved at 18:57:35, on 23-03-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programas\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programas\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Programas\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Programas\Messenger Plus! 3\MsgPlus.exe
C:\Programas\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\Windows Media Player\wmplayer.exe
C:\Programas\Internet Explorer\iexplore.exe
C:\Programas\MSN Apps\Updater\01.02.3000.1001\pt-br\msnappau.exe
C:\Documents and Settings\cliente\Definições locais\Temporary Internet Files\Content.IE5\GJDLNMB4\hijackthis[1].exe
C:\WINDOWS\SYSTEM32\cidaemon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://out.true-counter.com/c/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?101 (obfuscated)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vladimir-ramchenko.blogspot.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fbnet.pt/pcg/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?101 (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer disponibilizado por PC Guia
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
F1 - win.ini: run=msinfo.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programas\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programas\MSN Apps\MSN Toolbar\01.02.4000.1001\pt-br\msntb.dll
O2 - BHO: IEPlus Filter - {C97EAD04-D1D3-4580-BDAC-EB13B6CB176E} - C:\WINDOWS\fonts\font.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programas\MSN Apps\MSN Toolbar\01.02.4000.1001\pt-br\msntb.dll
O4 - HKLM..\Run: [IMJPMIG8.1] “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM..\Run: [AdaptecDirectCD] “C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe”
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Programas\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM..\Run: [CamMonitor] C:\Programas\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.dll,CMICtrlWnd
O4 - HKLM..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM..\Run: [QuickTime Task] “C:\Programas\QuickTime\qttask.exe” -atboottime
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [WildTangent CDA] RUNDLL32.exe “C:\Programas\WildTangent\Apps\CDA\cdaEngine0400.dll”,cdaEngineMain
O4 - HKLM..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe”
O4 - HKLM..\Run: [PicasaNet] “C:\Programas\Hello\Hello.exe” -b
O4 - HKLM..\Run: [C:\WINDOWS\system32\ope2D.exe ] C:\WINDOWS\system32\ope2D.exe
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programas\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU..\Run: [STYLEXP] C:\Programas\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe” /WinStart
O4 - HKCU..\Run: [msnmsgr] “C:\Programas\MSN Messenger\msnmsgr.exe” /background
O4 - Global Startup: Microsoft Office.lnk = C:\Programas\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra ‘Tools’ menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.fbnet.pt/pcg/
O16 - DPF: Toki Toki Boom - http://download.games.yahoo.com/games/clients/y/vto_x.cab
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/adobe/MTSInstallers/MetaStream3.cab?url=http://joao.leitao.free.fr/lapis/ThumbnailFrame.html
O16 - DPF: {15589FA1-C456-11CE-BF01-000000000000} - http://www.errornuker.com/products/errn2004/installers/default/ErrorNukerInstaller.exe
O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} - http://www.errorguard.com/installation/Install.cab
O16 - DPF: {33288993-5664-11D4-8B5B-00D0B73B3518} (ell Class) - http://www.easports.com/downloads/games/common/ieell.cab
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} - http://files.ea.com/downloads/rtpatch/v2/EARTPX.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/abarth/us/win/QuickTimeInstaller.exe
O16 - DPF: {86A88967-7A20-11D2-8EDA-00600818EDB1} - http://www.parallelgraphics.com/bin/cortvrml.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/binGame/ZAxRcMgr.cab
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/nike/nikefz4/install.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_3_16_0.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O19 - User stylesheet: C:\WINDOWS\Web\oslogo.bmp (file missing)
O19 - User stylesheet: C:\WINDOWS\default.css (HKLM)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

Ufff
:o That was a lot
Btw i couldn’t find the files in the task manager :frowning:
and the system restore was already shut off yesterday
Thanx :wink:

Hi mariohugo,

Make sure system restore is still off, then:


THESE ITEMS ARE EITHER HARMFULL OR A SECURITY RISK
WE STRONGLY RECOMMEND TO FIX THEM :

r1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://out.true-counter.com/b/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://out.true-counter.com/b/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://out.true-counter.com/a/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://out.true-counter.com/b/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://out.true-counter.com/c/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://out.true-counter.com/b/?101 (obfuscated)
r0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://vladimir-ramchenko.blogspot.com/
r1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.fbnet.pt/pcg/
r1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://out.true-counter.com/c/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://out.true-counter.com/b/?101 (obfuscated)
r1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer disponibilizado por PC Guia
r0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hiperligações
f1 - win.ini: run=msinfo.exe
o2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programas\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
o2 - BHO: IEPlus Filter - {C97EAD04-D1D3-4580-BDAC-EB13B6CB176E} - C:\WINDOWS\fonts\font.dll
o4 - HKLM..\Run: [C:\WINDOWS\system32\ope2D.exe ] C:\WINDOWS\system32\ope2D.exe
o16 - dpf: toki toki boom - http://download.games.yahoo.com/games/clients/y/vto_x.cab
o16 - dpf: yahoo! chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
o16 - dpf: {03f998b2-0e00-11d3-a498-00104b6eb52e} - https://components.viewpoint.com/adobe/mtsinstallers/metastream3.cab?url=http://joao.leitao.free.fr/lapis/thumbnailframe.html
o16 - dpf: {15589fa1-c456-11ce-bf01-000000000000} - http://www.errornuker.com/products/errn2004/installers/default/errornukerinstaller.exe
o16 - dpf: {205ff73b-ca67-11d5-99dd-444553540006} - http://www.errorguard.com/installation/install.cab
o16 - dpf: {33288993-5664-11d4-8b5b-00d0b73b3518} (ell class) - http://www.easports.com/downloads/games/common/ieell.cab
o16 - dpf: {54b52e52-8000-4413-bd67-fc7fe24b59f2} - http://files.ea.com/downloads/rtpatch/v2/eartpx.cab
o16 - dpf: {62475759-9e84-458e-a1ab-5d2c442adfde} - http://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/abarth/us/win/quicktimeinstaller.exe
o16 - dpf: {86a88967-7a20-11d2-8eda-00600818edb1} - http://www.parallelgraphics.com/bin/cortvrml.cab
o16 - dpf: {8e0d4de5-3180-4024-a327-4dfad1796a8d} (messengerstatsclient class) - http://messenger.zone.msn.com/binary/messengerstatsclient.cab31267.cab
o16 - dpf: {9aa73f41-ec64-489e-9a73-9cd52e528bc4} (zoneaxrcmgr class) - http://zone.msn.com/bingame/zaxrcmgr.cab
o16 - dpf: {ab29a544-d6b4-4e36-a1f8-d3e34fc7b00a} (wthoster class) - http://install.wildtangent.com/bgn/partners/nike/nikefz4/install.cab
o16 - dpf: {b38870e4-7ecb-40da-8c6a-595f0a5519ff} (msnmessengersetupdownloadcontrol class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
o16 - dpf: {b8be5e93-a60c-4d26-a2dc-220313175592} (zoneintro class) - http://zone.msn.com/binframework/v10/zintro.cab34246.cab
o16 - dpf: {d77ef652-9a6b-40c8-a4b9-1c0697c6cf41} (tikgames online control) - http://zone.msn.com/bingame/shpo/default/shapo.cab
o16 - dpf: {df780f87-ff2b-4df8-92d0-73db16a1543a} (popcaploader object) - http://zone.msn.com/bingame/apop/default/popcaploader_v5.cab
o16 - dpf: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_3_16_0.cab
o16 - dpf: {f58e1cef-a068-4c15-ba5e-587caf3ee8c6} (msn chat control 4.5) - http://chat.msn.com/bin/msnchat45.cab
o19 - user stylesheet: c:\windows\web\oslogo.bmp (file missing)


THE FOLLOWING ITEMS ARE NOT NEEDED TO LOAD
AT BOOTTIME FOR THE SYSTEM TO WORK PROPERLY,
THESE ARE UP TO YOU :

o4 - global startup: microsoft office.lnk = c:\programas\microsoft office\office10\osa.exe
o8 - extra context menu item: e&xportar para o microsoft excel - res://c:\progra~1\micros~2\office10\excel.exe/3000
o4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Programas\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
o4 - HKLM..\Run: [QuickTime Task] “C:\Programas\QuickTime\qttask.exe” -atboottime
o4 - HKLM..\Run: [WildTangent CDA] RUNDLL32.exe “C:\Programas\WildTangent\Apps\CDA\cdaEngine0400.dll”,cdaEngineMain
o4 - HKLM..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe”
o4 - HKLM..\Run: [PicasaNet] “C:\Programas\Hello\Hello.exe” -b
o4 - HKCU..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe” /WinStart
o14 - IERESET.INF: START_PAGE_URL=http://www.fbnet.pt/pcg/

Then run CWshredder: http://cwshredder.net/bin/CWShredder.exe

Then run Ad-Aware: http://download.com.com/3000-2144-10045910.html?part=69274&subj=dlpage&tag=button (update first)

Then Run Spybot: http://www.safer-networking.org/ (update first)

Then run another boot time scan with avast and remove everything it finds. (update first)

Then run ccleaner: http://www.filehippo.com/download_ccleaner.html

Also i see no active running firewall on your system, so if your not using a hardware firewall (usually in a router) then i suggest downloading a free one called Zonealarm: http://download.zonelabs.com/bin/free/1012_zl/zlsSetup_55_062_011.exe

Then reboot your system.

Then redo and repost your hijackthis log so we can confirm your clean.

P.S, i release there is alot of steps there, so just take your time, no need to rush, and post back when/if you need help with them.

–lee

Here it is the log file lee

Logfile of HijackThis v1.99.1
Scan saved at 19:08:25, on 24-03-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Programas\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\system32\RunDll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programas\Messenger Plus! 3\MsgPlus.exe
C:\Programas\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programas\Internet Explorer\iexplore.exe
C:\Programas\MSN Apps\Updater\01.02.3000.1001\pt-br\msnappau.exe
C:\Documents and Settings\cliente\Definições locais\Temporary Internet Files\Content.IE5\GJDLNMB4\hijackthis[1].exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programas\MSN Apps\MSN Toolbar\01.02.4000.1001\pt-br\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programas\MSN Apps\MSN Toolbar\01.02.4000.1001\pt-br\msntb.dll
O4 - HKLM..\Run: [IMJPMIG8.1] “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM..\Run: [AdaptecDirectCD] “C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe”
O4 - HKLM..\Run: [CamMonitor] C:\Programas\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.dll,CMICtrlWnd
O4 - HKLM..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe”
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programas\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU..\Run: [STYLEXP] C:\Programas\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe” /WinStart
O4 - HKCU..\Run: [msnmsgr] “C:\Programas\MSN Messenger\msnmsgr.exe” /background
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra ‘Tools’ menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

Well that seemed to solved the trojan problem but now it gives me a brand new error >:( lol when i shut the computer off there is a message that says that there is an error with the file AshServ.exe I cannot read the rest of the message because it is very quick, once again thank you for your help, can you help me once again?

PS: My windows firewall says it is turned on should i download zonealarm anyway?

Hi

Log looks clean.

About the firewall, Windows firewall is only Inbound protection, but some people are fine with this, you can see the differences here: http://www.securetec.com.au/lockdown/compare.htm

About the error, does a repair of avast help? (Control pannel > Add/Remove programs > Avast > change/remove >Repair)

–lee

Hi

Now i have an even bigger trouble, the pc only starts in safe mode (!). While loading win xp it stops and then a blue screen appears but i cannot read it cause it disapears very quickly, this appened after i installed zone alarm, i already uninstaled zone alarm but it keeps happening, after the blue screen it restarts and then it only enters in safe mode, i tried to use a boot disk but it’s useless. What should i do??

Try rebooting a couple of times.

If that doesn’t work reboot the PC and tap F8 while you wait for boot options to be displayed for you. Once there, choose “Last known good configuration.”

You could try repairing XP if you feel the need to: http://www.help2go.com/article209.html

–lee

I cannot fix XP and the last good configuration gives the same error, i noticed that every time the pc restarts it doesn’t recognize the hard disk only if i shut off the computer and then turn it on again. I also tried to fixboot but it didn’t work i don’t know what else to do :frowning:

If you can get into safe mode, run system restore and restore your computer back to before the problem occured.

Well the problem is solved, i re-installed XP without loosing any data (i couldn’t use sistem retore because it had been disabled before) now it’s boring cause i got to download sp2 again :frowning: but thanks for your help you all now the computer is quite faster ;D

Life and Windows can be a pain/pane at times.

If you are going to download SP2 again, make sure that you download the full version and not the windows update to SP2 (e.g. the download and install on-line, as only elements that require update are downloaded. leaving you in the same position if you ever need to re-install XP). The full SP2 update is about 266MB, but once you have downloaded it, burn it to a CD, then you have a copy of SP2 you can use over and over if needed.

You can ‘join’ the original CD of Windows XP (Home, Pro or Corporate Edition) with the SP2 updates using AutoStreamer.

Follow the instructions on screen to create an ISO file that could should be burned into another CD.
If you install Windows from this new CD, SP2 will be automatically installed!

Hi there

Same problem again, avast warned me about the virus when i turned on the pc some time ago, i already tried the same steps that lee16 gave me previously but he keeps showing up, the problem is that i don’t know wich files to erase with hijackthis, here is the log, hopefully somebody can help me.
Btw i installed the zonealarm firewall but the pc turns extra slow and it takes almost 10 minutes tu completely turn on win xp so i had to unistalled it.

Logfile of HijackThis v1.99.1
Scan saved at 10:04:34, on 09-04-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
C:\Programas\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Programas\Alwil Software\Avast4\ashMaiSv.exe
C:\Programas\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.exe
C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programas\Java\jre1.5.0_02\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programas\MSN Messenger\msnmsgr.exe
C:\Programas\MSN Apps\Updater\01.02.3000.1001\pt-br\msnappau.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\cliente\Definições locais\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.btuga.com/
F2 - REG:system.ini: Shell=Explorer.exe winsock.scr
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programas\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programas\MSN Apps\MSN Toolbar\01.02.4000.1001\pt-br\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programas\MSN Apps\MSN Toolbar\01.02.4000.1001\pt-br\msntb.dll
O4 - HKLM..\Run: [IMJPMIG8.1] “C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM..\Run: [AdaptecDirectCD] “C:\Programas\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe”
O4 - HKLM..\Run: [Cmaudio] RunDll32 cmicnfg.dll,CMICtrlWnd
O4 - HKLM..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programas\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [dxset.exe] C:\WINDOWS\dxsetu.exe
O4 - HKCU..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU..\Run: [MessengerPlus3] “C:\Programas\Messenger Plus! 3\MsgPlus.exe” /WinStart
O4 - HKCU..\Run: [msnmsgr] “C:\Programas\MSN Messenger\msnmsgr.exe” /background
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra ‘Tools’ menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programas\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra ‘Tools’ menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programas\Messenger\msmsgs.exe
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programas\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programas\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programas\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programas\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

This is it! :wink:

You don’t seem to have a software firewall. If you would like one, I can suggest a few.

Hi

Remove these:

F2 - REG:system.ini: Shell=Explorer.exe winsock.scr
O4 - HKLM..\Run: [dxset.exe] C:\WINDOWS\dxsetu.exe
O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:\PROGRA~1\DAP\dapextie2.htm
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab

Then remove this file:
C:\WINDOWS[b]dxsetu.exe[/b]

Then run any spyware scanners you have on your PC. (Spybot/Ad-aware etc)
Then run a boot time scan with avast. (Open avast > Menu (top left hand corner) > Boot Time Scan)

Then run ccleaner: http://www.filehippo.com/download/ncAOCJr-Om3Lq35Rh3QQoQ2/download.html

Then post back to let us know if the problem is solved or not :wink:

–lee