Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc  
Forum Quick Jump
 
New Topic Locked Topic Printable version of : Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
[ << Previous Thread | Next Thread >> ]

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-9-2007 4:13 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Hi, I'm having a horrible time with this one.  It has my computer near frozen, plus the disabled taskmanager and regeditor.  Browsers barely function, took me 30 minutes to get onto this site to post this ad.  Here's my Hijack this.  Any help would be appreciated.
 
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 9:31:55 PM, on 9/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\BitDefender\BitDefender 2008\seccenter.exe
C:\Program Files\HijackThis\HiJackThis_v2.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wsnpoem.exe,
O1 - Hosts: 127.255.255.255 www.getright.com
O1 - Hosts: 127.255.255.255 pro.getright.com
O1 - Hosts: 127.255.255.255 www.headlightinc.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {709DECC3-EBE5-46B4-8C17-35D3B425DDC2} - C:\WINDOWS\system32\ddccy.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O2 - BHO: (no name) - {CF46BFB3-2ACC-441b-B82B-36B9562C7FF1} - C:\WINDOWS\system32\xpsiuswx.dll (file missing)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [pipmon] pipmon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Ad-Aware\AdAware\Ad-Watch.exe"
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinrldt.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - c:\program files\getright\grdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - c:\program files\getright\grbrowse.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183172622406
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: efccbcb - efccbcb.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: cankered - {44e670f2-d57b-4815-a576-955d17dbbf2d} - C:\WINDOWS\system32\dooep.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: DomainService - Unknown owner - (no file)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 9006 bytes
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-9-2007 8:48 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Hi JSchuler scool
 
 
 
Click here - ->>  Before posting a log 
 
 
 After You have run the scan tools -
 
Reboot normally
 
Post Hijackthis log along with AVG Anti-Spyware log, C: Rootlog TXT, C: combofix txt in this topic
 
 


Do NOT post your problem in someone elses thread.
Start a new topic so that it may receive proper attention. 
 

Back to Top
 

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-10-2007 4:29 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
O.K. Here are the logs requested. At the end of combofix before the reboot it tried to write three files I believe and said they all three failed.

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:03:18 PM 9/9/2007

+ Scan result:



C:\Documents and Settings\Kids\Cookies\kids@www.adobe.txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@connextra.txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@cpvfeed.txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@ehg-dig.hitbox.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@search.msn.txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@ssl-hints.netflame.txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@www.paypal.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Kids\Cookies\kids@m.webtrends.txt -> TrackingCookie.Webtrends : Cleaned.
C:\WINDOWS\system32\wapisvit32.exe -> Trojan.Small : Cleaned with backup (quarantined).


::Report end



********************************* ROOTCHK-(22-08-07)-LOG, by ejvindh
Sun 09/09/2007 21:16:59.76

Driver Core (visible) is present. Run COMBOFIX by sUBs or SDFIX by AndyManchesta.
Driver xpdx (hidden) is present. Run RUSTBFIX by Ejvindh, COMBOFIX by sUBs or SDFIX by AndyManchesta.

********************************* ROOTCHK-LOG-end




********************************* ROOTCHK-(22-08-07)-LOG, by ejvindh
Sun 09/09/2007 21:16:59.76

Driver Core (visible) is present. Run COMBOFIX by sUBs or SDFIX by AndyManchesta.
Driver xpdx (hidden) is present. Run RUSTBFIX by Ejvindh, COMBOFIX by sUBs or SDFIX by AndyManchesta.

********************************* ROOTCHK-LOG-end




Logfile of HijackThis v1.99.1
Scan saved at 22:21, on 2007-09-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HijackThis\alternativ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wsnpoem.exe,
O1 - Hosts: 127.255.255.255 www.getright.com
O1 - Hosts: 127.255.255.255 pro.getright.com
O1 - Hosts: 127.255.255.255 www.headlightinc.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {24B6E45D-48F7-49A2-8823-2A5001706AED} - C:\WINDOWS\system32\ddccy.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - c:\program files\getright\grdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - c:\program files\getright\grbrowse.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183172622406
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: efccbcb - efccbcb.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)

Once again thanks for the help
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-10-2007 4:43 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
 and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)
 and save it to your desktop.

When you have done this, please boot into Safe Mode (Tap F8 during startup).

Open the extracted folder  - C:\ SDFix  and doubleclick on RunThis.bat to start the script.

Type Y to begin the script. It will remove the Trojan Services then make some repairs to the registry and prompt you to press any key to Reboot. When you hit any key, your computer will reboot. Your system will take longer that normal to restart as the fixtool will be running and removing files.

When your desktop loads, the utility will complete the removal and display Finished. Press any key again to end the script and load your desktop icons.
 
 
 
 
Finally open the SDFix folder on your desktop and copy and paste the contents of Report.txt back in this thread along with fresh hijackthis log,  and tell how things are running


Do NOT post your problem in someone elses thread.

Back to Top
 

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-10-2007 5:55 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
I ran SDfix, browsers running fine again. Task manager and regedit are no longer disabled. Here are the results and thanks a million.


SDFix: Version 1.103

Run by Kari Sanders on 2007-09-09 at 23:30

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:

C:\269547~1 - Deleted



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Documents and Settings\Kari Sanders\My Documents\My Videos\Hid\Best.of.Jenna.Jameson[DVDrip][www.torrentgo.com]\Best.of.Jenna.Jameson[DVDrip][www.torrentgo.com].avi
C:\Documents and Settings\Kari Sanders\My Documents\My Videos\Hid\Best.of.Jenna.Jameson[DVDrip][www.torrentgo.com]\Thumbs.db
C:\Documents and Settings\Kari Sanders\My Documents\Torrent\[isoHunt] Layout (Briana Banks) XXX [DVDRIP][All Sex][www.sexotorrent.com].rar.torrent
C:\Documents and Settings\Kari Sanders\NetHood\insanemyth.com\Desktop.ini
C:\Documents and Settings\Kari Sanders\NetHood\members.aol.com\Desktop.ini
C:\Program Files\America Online 9.0\aolphx.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\America Online 9.0\RBM.exe
C:\Documents and Settings\Kari Sanders\My Documents\Torrent\[isoHunt] Layout (Briana Banks) XXX [DVDRIP][All Sex][www.sexotorrent.com].rar.torrent
C:\Documents and Settings\All Users\Application Data\GTek\GTUpdate\AUpdate\Channels\ch1\lock.tmp
C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
C:\WINDOWS\system32\yccdd.tmp
C:\WINDOWS\system32\config\SAM.tmp.LOG
C:\WINDOWS\system32\config\SECURITY.tmp.LOG

Finished!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-10-2007 6:28 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
That´s good news smilewinkgrin
 
 
You may want to read TonyKlein´s article  about how to prevent against  spyware/hijackers in the future
http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html                                       


Do NOT post your problem in someone elses thread.

Back to Top
 

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-10-2007 10:13 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Hi again.  I ran a bitdefender scan immediately after finishing up with you last night.  The results are below. The computer is still running laggy although better than it has in a couple of days.  Once I started trying to browse off of this site it was quite more congested.

BitDefender Log File
Product : BitDefender Total Security 2008
Version : BitDefender UIScanner v.11
Log date : 10:52:55 10/09/2007
Log path : C:\Documents and Settings\All Users\Application Data\BitDefender\Desktop\Profiles\Logs\full_scan\1189439575_9_02.xml

Scan Paths:
Path0000: C:\


Scan Options:
Scan for viruses : Yes
Scan for adware : Yes
Scan for spyware : Yes
Scan for applications : Yes
Scan for dialers : Yes
Scan for rootkits : Yes


Target selection options:
Scan registry keys : No
Scan cookies : Yes
Scan boot sectors : Yes
Scan memory processes : Yes
Scan archives : No
Scan runtime packers : Yes
Scan email : Yes
Scan all files : No
Heuristic Scan : Yes
Scanned extenstions : (null)
Exclude extensions :


Target Processing
Default action for infected objects : Disinfect
Default action for suspicious objects : None
Default action for hidden objects : None


Scan engines summary
Number of virus signatures : 871889
Archive plugins : 41
Email plugins : 6
Scan plugins : 12
Archive plugins : 41
System plugins : 4
Unpack plugins : 7


Overall scan summary
Scanned items : 81572
Infected items : 12
Suspicious items : 0
Resolved items : 0
Individual viruses found : 11
Scanned directories : 5723
Scanned boot sectors : 2
Scanned archives : 36
Input-output errors : 25
Scan time : 00:01:98:5935
Files per second : 13


Scanned files summary
Scanned : 79689
Infected : 12


Scanned processes summary
Scanned : 32
Infected : 0


Scanned registry keys summary
Scanned : 1851
Infected : 0


Scanned cookies summary
Scanned : 0
Infected : 0


Remaining issues:
Object Name Threat Name Final Status
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278287.exe Adware.Mirar.AI Disinfect Failed,
C:\Documents and Settings\Kari Sanders\Local Settings\Temporary Internet Files\Content.IE5\F9GDSJ0K\jaun_20070726[1] Adware.Virtumonde.GGC Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278286.exe Adware.Zenosearch.O Disinfect Failed,
C:\WINDOWS\system32\ddccy.dll DeepScan:Generic.Virtumonde.1.2BEBF2D4 Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP977\A0281474.sys Rootkit.Agent.EV Disinfect Failed,
C:\Documents and Settings\Kari Sanders\Local Settings\Temporary Internet Files\Content.IE5\KXQTBTZ3\lkjh[1] Trojan.Clicker.Agent.NP Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278288.exe Trojan.Downloader.Small.BUY Disinfect Failed,
C:\Documents and Settings\Kari Sanders\Local Settings\Temporary Internet Files\Content.IE5\F9GDSJ0K\valera[1] Trojan.Fotomoto.E Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0279345.exe Trojan.Fotomoto.E Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278289.exe Trojan.Horse.AZT Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278290.exe Trojan.LiveProtect.A Disinfect Failed,
C:\System Volume Information\_restore{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278285.exe Trojan.Muldrop.AHD Disinfect Failed,


Resolved issues:
Object Name Threat Name Final Status


Back to Top
 

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-10-2007 10:24 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
One more thing I forgot to mention.  After running ComboFix the clock never got reset back to its origional setting and will no longer sinchronize online.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-11-2007 8:05 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Please download Free  Version of Superantispyware
 
Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it.
close the program
 
 
Please download ATF Cleaner:
 http://www.atribune.org/ccount/click.php?id=1 by Atribune.
This program is for XP and Windows 2000 only
 
 
Download and install DrWebCureit:
 
to your desktop.
 
 
 
 
Please print out or copy this page to Notepad as you will be in Safe Mode and unable to refer to this page.
 
 
 
 
 
 
 
 
Double click ATF-Cleaner.exe to run the program.
Check the boxes to the left of:
Windows Temp
Current User Temp
All Users Temp
Temporary Internet Files
Prefetch (Windows XP) only.
Java Cache
Recycle Bin
NB. It's normal after running ATF cleaner that the PC will be slower to boot the first time.
 
 
Doubleclick the "drweb-cureit.exe" and click "ok" in the prompt window that will open , asking "start the express scan now".
It will first make a quick scan of your system, let it clean what it find, and when it says "done"
Click on the green screwdriver-
Actions Tab- Adware-Dialers-Riskware-Hacktools, use dropdown menu and select -Delete
Click on the drive(s) you want to scan . A red dot will mark the selected drive(s) . Then hit the green  arrow in lower right corner It will now scan your  drive(s), say yes to all
 
After the scan, in the Dr.Web CureIt menu on top, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
Close Dr.Web Cureit.
 
Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
 
 
 
 
Start Superantispyware.
Hit - Scan Your Computer - button
Click on the drive(s) you want to scan. Put a check in - Perform Complete Scan, then next,
it will scan now. When scan have finished, put a checkmark with  all items it found. Next, after cleaning, allow it to Reboot
 
 
 
Start Superantispyware again –
Click Preferences and then click the statistics/logs tab.
Click the dated log and press view log and a text file will appear.
 
 
 
Post this log along with fresh hijackthis log, Dr.Web log and tell how things are running  ?
 
 
 
 
 
 
 
 
 
 
 


Do NOT post your problem in someone elses thread.

Back to Top
 

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-12-2007 3:02 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
ATF ran just fine, drweb crashed about 1/2 way through on microsoft antispyware error log file. It's only finds at that point were the aim WxBug.exe, ComboFIX, and the bitdefender updater. Should I try to run it again or move on to the superantispyware. Bitdefender is still constantly blocking viruses on the computer.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-12-2007 9:07 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Go offline, disable/deactivate bitdefender, then run Superantispyware


Do NOT post your problem in someone elses thread.

Back to Top
 

JSchuler
New Member


Date Joined Sep 2007
Total Posts : 8
 
   Posted 9-13-2007 4:11 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Here are the superantispyware logs. I forget why I ran it four times but here is. I really like this SantiSpyware program. It did me good. The computer is running near squeaky clean now, the clock seems to be synchronizing. The only thing that isn't working seems to be the printer so I'm going to try and reload the driver. Anyways here they are.

1-SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/11/2007 at 09:12 AM

Application Version : 3.9.1008

Core Rules Database Version : 3304
Trace Rules Database Version: 1310

Scan type : Quick Scan
Total Scan Time : 00:00:01

Memory items scanned : 0
Memory threats detected : 0
Registry items scanned : 0
Registry threats detected : 0
File items scanned : 1
File threats detected : 1

Trojan.WinFixer
C:\WINDOWS\SYSTEM32\DDCCY.DLL


2- SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/11/2007 at 10:29 AM

Application Version : 3.9.1008

Core Rules Database Version : 3304
Trace Rules Database Version: 1310

Scan type : Quick Scan
Total Scan Time : 01:08:28

Memory items scanned : 352
Memory threats detected : 1
Registry items scanned : 762
Registry threats detected : 90
File items scanned : 11942
File threats detected : 25

Trojan.WinFixer
C:\WINDOWS\SYSTEM32\DDCCY.DLL
C:\WINDOWS\SYSTEM32\DDCCY.DLL
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F7CB206B-3506-432C-9648-00E9ABB04C07}
HKCR\CLSID\{F7CB206B-3506-432C-9648-00E9ABB04C07}
HKCR\CLSID\{F7CB206B-3506-432C-9648-00E9ABB04C07}\InprocServer32
HKCR\CLSID\{F7CB206B-3506-432C-9648-00E9ABB04C07}\InprocServer32#ThreadingModel

Adware.Tracking Cookie
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@advertising.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@questionmarket.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@statse.webtrendslive.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@fastclick.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@ads.pointroll.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@interclick.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@atdmt.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@tacoda.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@adbrite.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@indextools.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@doubleclick.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@www.burstbeacon.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@homestore.122.2o7.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@anat.tacoda.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@superstats.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@ehg-dig.hitbox.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@anad.tacoda.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@ads.adbrite.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@statcounter.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@cpvfeed.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@partner2profit.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@tribalfusion.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@hitbox.txt
C:\Documents and Settings\Kari Sanders\Cookies\kari_sanders@www.burstnet.txt

Malware.SpyLocked
HKCR\TypeLib\{099A05C2-CDA0-41FF-9A38-DD8B6149A766}
HKCR\TypeLib\{099A05C2-CDA0-41FF-9A38-DD8B6149A766}\1.0
HKCR\TypeLib\{099A05C2-CDA0-41FF-9A38-DD8B6149A766}\1.0\0
HKCR\TypeLib\{099A05C2-CDA0-41FF-9A38-DD8B6149A766}\1.0\0\win32
HKCR\TypeLib\{099A05C2-CDA0-41FF-9A38-DD8B6149A766}\1.0\FLAGS
HKCR\TypeLib\{099A05C2-CDA0-41FF-9A38-DD8B6149A766}\1.0\HELPDIR
HKCR\Interface\{2F223FDC-164A-492C-82D0-055FD8CE349C}
HKCR\Interface\{2F223FDC-164A-492C-82D0-055FD8CE349C}\ProxyStubClsid
HKCR\Interface\{2F223FDC-164A-492C-82D0-055FD8CE349C}\ProxyStubClsid32
HKCR\Interface\{2F223FDC-164A-492C-82D0-055FD8CE349C}\TypeLib
HKCR\Interface\{2F223FDC-164A-492C-82D0-055FD8CE349C}\TypeLib#Version
HKCR\Interface\{4D3BC08F-3C13-4CD1-80F4-F5A7B7D0388F}
HKCR\Interface\{4D3BC08F-3C13-4CD1-80F4-F5A7B7D0388F}\ProxyStubClsid
HKCR\Interface\{4D3BC08F-3C13-4CD1-80F4-F5A7B7D0388F}\ProxyStubClsid32
HKCR\Interface\{4D3BC08F-3C13-4CD1-80F4-F5A7B7D0388F}\TypeLib
HKCR\Interface\{4D3BC08F-3C13-4CD1-80F4-F5A7B7D0388F}\TypeLib#Version
HKCR\Interface\{5BA3EE9B-A96E-4301-B839-388AFEFCD9F4}
HKCR\Interface\{5BA3EE9B-A96E-4301-B839-388AFEFCD9F4}\ProxyStubClsid
HKCR\Interface\{5BA3EE9B-A96E-4301-B839-388AFEFCD9F4}\ProxyStubClsid32
HKCR\Interface\{5BA3EE9B-A96E-4301-B839-388AFEFCD9F4}\TypeLib
HKCR\Interface\{5BA3EE9B-A96E-4301-B839-388AFEFCD9F4}\TypeLib#Version
HKCR\Interface\{85292BEE-65FF-41AD-8E72-B385D1C93C89}
HKCR\Interface\{85292BEE-65FF-41AD-8E72-B385D1C93C89}\ProxyStubClsid
HKCR\Interface\{85292BEE-65FF-41AD-8E72-B385D1C93C89}\ProxyStubClsid32
HKCR\Interface\{85292BEE-65FF-41AD-8E72-B385D1C93C89}\TypeLib
HKCR\Interface\{85292BEE-65FF-41AD-8E72-B385D1C93C89}\TypeLib#Version
HKCR\Interface\{861ADDA2-0216-49AC-AA5B-62F64F1D91D1}
HKCR\Interface\{861ADDA2-0216-49AC-AA5B-62F64F1D91D1}\ProxyStubClsid
HKCR\Interface\{861ADDA2-0216-49AC-AA5B-62F64F1D91D1}\ProxyStubClsid32
HKCR\Interface\{861ADDA2-0216-49AC-AA5B-62F64F1D91D1}\TypeLib
HKCR\Interface\{861ADDA2-0216-49AC-AA5B-62F64F1D91D1}\TypeLib#Version
HKCR\Interface\{8D3014AE-0854-4222-A733-D9DD0149D9FA}
HKCR\Interface\{8D3014AE-0854-4222-A733-D9DD0149D9FA}\ProxyStubClsid
HKCR\Interface\{8D3014AE-0854-4222-A733-D9DD0149D9FA}\ProxyStubClsid32
HKCR\Interface\{8D3014AE-0854-4222-A733-D9DD0149D9FA}\TypeLib
HKCR\Interface\{8D3014AE-0854-4222-A733-D9DD0149D9FA}\TypeLib#Version
HKCR\Interface\{9A9E938C-4A18-4B36-A973-DADCD8A1C268}
HKCR\Interface\{9A9E938C-4A18-4B36-A973-DADCD8A1C268}\ProxyStubClsid
HKCR\Interface\{9A9E938C-4A18-4B36-A973-DADCD8A1C268}\ProxyStubClsid32
HKCR\Interface\{9A9E938C-4A18-4B36-A973-DADCD8A1C268}\TypeLib
HKCR\Interface\{9A9E938C-4A18-4B36-A973-DADCD8A1C268}\TypeLib#Version
HKCR\Interface\{9C4D0D3F-F36E-42A3-9B35-A43C08AB1866}
HKCR\Interface\{9C4D0D3F-F36E-42A3-9B35-A43C08AB1866}\ProxyStubClsid
HKCR\Interface\{9C4D0D3F-F36E-42A3-9B35-A43C08AB1866}\ProxyStubClsid32
HKCR\Interface\{9C4D0D3F-F36E-42A3-9B35-A43C08AB1866}\TypeLib
HKCR\Interface\{9C4D0D3F-F36E-42A3-9B35-A43C08AB1866}\TypeLib#Version
HKCR\Interface\{ABD41A08-5C4D-4CDB-8310-A681E73755BF}
HKCR\Interface\{ABD41A08-5C4D-4CDB-8310-A681E73755BF}\ProxyStubClsid
HKCR\Interface\{ABD41A08-5C4D-4CDB-8310-A681E73755BF}\ProxyStubClsid32
HKCR\Interface\{ABD41A08-5C4D-4CDB-8310-A681E73755BF}\TypeLib
HKCR\Interface\{ABD41A08-5C4D-4CDB-8310-A681E73755BF}\TypeLib#Version
HKCR\Interface\{B151B421-A97B-4C1D-B555-EED8A35BA5C8}
HKCR\Interface\{B151B421-A97B-4C1D-B555-EED8A35BA5C8}\ProxyStubClsid
HKCR\Interface\{B151B421-A97B-4C1D-B555-EED8A35BA5C8}\ProxyStubClsid32
HKCR\Interface\{B151B421-A97B-4C1D-B555-EED8A35BA5C8}\TypeLib
HKCR\Interface\{B151B421-A97B-4C1D-B555-EED8A35BA5C8}\TypeLib#Version
HKCR\Interface\{B3D80493-3013-4E93-A878-4CEFC401F4A6}
HKCR\Interface\{B3D80493-3013-4E93-A878-4CEFC401F4A6}\ProxyStubClsid
HKCR\Interface\{B3D80493-3013-4E93-A878-4CEFC401F4A6}\ProxyStubClsid32
HKCR\Interface\{B3D80493-3013-4E93-A878-4CEFC401F4A6}\TypeLib
HKCR\Interface\{B3D80493-3013-4E93-A878-4CEFC401F4A6}\TypeLib#Version
HKCR\Interface\{BDC7BB72-6C19-415D-86C3-76CC46EC00A9}
HKCR\Interface\{BDC7BB72-6C19-415D-86C3-76CC46EC00A9}\ProxyStubClsid
HKCR\Interface\{BDC7BB72-6C19-415D-86C3-76CC46EC00A9}\ProxyStubClsid32
HKCR\Interface\{BDC7BB72-6C19-415D-86C3-76CC46EC00A9}\TypeLib
HKCR\Interface\{BDC7BB72-6C19-415D-86C3-76CC46EC00A9}\TypeLib#Version
HKCR\Interface\{CE351B84-F0D6-4FA0-AAD7-3C0616EA647E}
HKCR\Interface\{CE351B84-F0D6-4FA0-AAD7-3C0616EA647E}\ProxyStubClsid
HKCR\Interface\{CE351B84-F0D6-4FA0-AAD7-3C0616EA647E}\ProxyStubClsid32
HKCR\Interface\{CE351B84-F0D6-4FA0-AAD7-3C0616EA647E}\TypeLib
HKCR\Interface\{CE351B84-F0D6-4FA0-AAD7-3C0616EA647E}\TypeLib#Version
HKCR\Interface\{D64DCDAE-38CD-488C-A85C-00A0B5C03AE8}
HKCR\Interface\{D64DCDAE-38CD-488C-A85C-00A0B5C03AE8}\ProxyStubClsid
HKCR\Interface\{D64DCDAE-38CD-488C-A85C-00A0B5C03AE8}\ProxyStubClsid32
HKCR\Interface\{D64DCDAE-38CD-488C-A85C-00A0B5C03AE8}\TypeLib
HKCR\Interface\{D64DCDAE-38CD-488C-A85C-00A0B5C03AE8}\TypeLib#Version
HKCR\Interface\{D9F4D801-2431-465A-B754-AB9E3B649E8C}
HKCR\Interface\{D9F4D801-2431-465A-B754-AB9E3B649E8C}\ProxyStubClsid
HKCR\Interface\{D9F4D801-2431-465A-B754-AB9E3B649E8C}\ProxyStubClsid32
HKCR\Interface\{D9F4D801-2431-465A-B754-AB9E3B649E8C}\TypeLib
HKCR\Interface\{D9F4D801-2431-465A-B754-AB9E3B649E8C}\TypeLib#Version
HKCR\Interface\{E0DBB136-FCD7-4180-9207-D4A9E822002E}
HKCR\Interface\{E0DBB136-FCD7-4180-9207-D4A9E822002E}\ProxyStubClsid
HKCR\Interface\{E0DBB136-FCD7-4180-9207-D4A9E822002E}\ProxyStubClsid32
HKCR\Interface\{E0DBB136-FCD7-4180-9207-D4A9E822002E}\TypeLib
HKCR\Interface\{E0DBB136-FCD7-4180-9207-D4A9E822002E}\TypeLib#Version

3-SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/11/2007 at 01:23 PM

Application Version : 3.9.1008

Core Rules Database Version : 3304
Trace Rules Database Version: 1310

Scan type : Complete Scan
Total Scan Time : 01:17:13

Memory items scanned : 323
Memory threats detected : 0
Registry items scanned : 6638
Registry threats detected : 0
File items scanned : 61216
File threats detected : 1

Trojan.Unknown Origin
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP976\A0280446.EXE


4-SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 09/11/2007 at 07:42 PM

Application Version : 3.9.1008

Core Rules Database Version : 3304
Trace Rules Database Version: 1310

Scan type : Complete Scan
Total Scan Time : 00:55:06

Memory items scanned : 341
Memory threats detected : 0
Registry items scanned : 6626
Registry threats detected : 0
File items scanned : 60984
File threats detected : 5

Trojan.Rootkit-TnCore/Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278285.EXE

Adware.ZenoSearch
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278286.EXE

Trojan.Downloader-Gen/Suspicious
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0278290.EXE

Adware.eZula
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP975\A0279345.EXE

Trojan.Rootkit-TnCore
C:\SYSTEM VOLUME INFORMATION\_RESTORE{D07B2617-2477-4A4E-A4DD-8AE553529BA0}\RP977\A0281474.SYS

AND HERE IS THE HIJACK THIS

Logfile of HijackThis v1.99.1
Scan saved at 10:10, on 2007-09-12
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\alternativ.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Download with GetRight - c:\program files\getright\grdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - c:\program files\getright\grbrowse.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\WINDOWS\System32\shdocvw.dll (HKCU)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1183172622406
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Service Client v.3.4) - http://ccon.futuremark.com/global/msc34.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: efccbcb - efccbcb.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe" /service (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe" /service (file missing)
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 9-13-2007 6:19 (GMT +1)    Quote: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etcAlert an admin about: Can't shake this virus... Fotomoto.E, regedit locked up, taskmanager, etc
Run Hijackthis and place a check beside each of the following. Close all other browser windows except HJT.
Click fix checked:
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (file missing)