Name: Tony Montana Date: September 30, 2007 at 08:38:47 Pacific Subject: Malware Threats/ Trojan TJ/BZ OS: Windows XP Pro CPU/Ram: Intel Core2 504MB Model/Manufacturer: Toshiba Satellite Pro
Comment:
I am getting Pop Ups regarding Malware Threats and Trojan TJ/BZ,I have the log for Hijack this if needed
!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!
Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd" Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Please download and install the latest version of HijackThis v2.0.2:
Download the HijackThis Installer from this link: HijackThis
1. Save " HJTInstall.exe" to your desktop. 2. Double click on HJTInstall.exe to run the program. 3. By default it will install to C:\Program Files\Trend Micro\HijackThis. 4. Accept the license agreement by clicking the "I Accept" button. 5.Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log. 6. Click "Save log" to save the log file and then the log will open in Notepad. 7. Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log. 8. Paste the log in your next reply. 9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
Logfile of HijackThis v1.99.1 Scan saved at 16:24:58, on 30/09/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Temporarily disable any of the following anti-spyware realtime protection programs that you may have in the provided link along with Norton's scriptblocking as they will sotp the removal tools from working.
Disable Realtime Protection or the fixes will not work. Be sure to turn yout anti-spyware programs back on once the computer is clean.
Turn off Norton's ScriptBlocking:
To disable Norton AntiVirus Script Blocking:
Start Norton AntiVirus. If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program. Click Options. If you see a menu, click Norton AntiVirus. In the left pane, click Script Blocking. In the right pane, uncheck Enable Script Blocking (recommended). Click OK.
!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!
Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd" Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Please download and install
SuperAntiSpyware Load SUPERAntiSpyware and click the Check for Updates button. Once the update has finished, click the Scan your Computer button. Check Perform Complete Scan and then click Next. SUPERAntiSpyware will now scan your computer, and when it’s finished it will list all the infections it has found. Make sure that they all have a check next to them, and then click Next. Click Finish and you will be taken back to the main interface. It could be possible that it will ask you to reboot your computer in order to delete some files after reboot. I'll need a log afterwards of what has been found. To get the log, click Preferences and then click the Statistics/Logs tab. Click the dated log and press View Log and a text file will appear. Please post the results of the SUPERAntiSpyware log and a new HijackThis log in your next reply.
Scan done at 17:07:34.71, 02/10/2007 Run from C:\Documents and Settings\Karl\Desktop OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\System32\GEARSec.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe C:\PROGRA~1\NORTON~1\NORTON~1\NPROTECT.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\PROGRA~1\NORTON~1\NORTON~1\SPEEDD~1\NOPDB.EXE C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\ThpSrv.exe C:\WINDOWS\system32\wdfmgr.exe C:\Program Files\Online Image Add-on\icthis.exe C:\Program Files\Online Image Add-on\icmntr.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Karl »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Karl\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Karl\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\Online Image Add-on\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel(R) PRO/1000 PL Network Connection - Packet Scheduler Miniport DNS Server Search Order: 194.168.4.100 DNS Server Search Order: 194.168.8.100 HKLM\SYSTEM\CCS\Services\Tcpip\..\{4F36FE02-41C7-420A-A2C2-F9866CFE1EFA}: DhcpNameServer=194.168.4.100 194.168.8.100 HKLM\SYSTEM\CS1\Services\Tcpip\..\{4F36FE02-41C7-420A-A2C2-F9866CFE1EFA}: DhcpNameServer=194.168.4.100 194.168.8.100 HKLM\SYSTEM\CS2\Services\Tcpip\..\{4F36FE02-41C7-420A-A2C2-F9866CFE1EFA}: DhcpNameServer=194.168.4.100 194.168.8.100 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=194.168.4.100 194.168.8.100 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=194.168.4.100 194.168.8.100 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»»
EndLogfile of HijackThis v1.99.1 Scan saved at 18:15:31, on 02/10/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Adware.Tracking Cookie C:\Documents and Settings\Karl\Cookies\karl@atdmt[2].txt C:\Documents and Settings\Karl\Cookies\karl@stats1.reliablestats[1].txt C:\Documents and Settings\Karl\Cookies\karl@cgi-bin[2].txt C:\Documents and Settings\Karl\Cookies\karl@adrevenue[2].txt C:\Documents and Settings\Karl\Cookies\karl@s[1].txt C:\Documents and Settings\Karl\Cookies\karl@adopt.euroclick[2].txt C:\Documents and Settings\Karl\Cookies\karl@clickbank[1].txt C:\Documents and Settings\Karl\Cookies\karl@serving-sys[1].txt C:\Documents and Settings\Karl\Cookies\karl@advertising[1].txt C:\Documents and Settings\Karl\Cookies\karl@media.adrevolver[1].txt C:\Documents and Settings\Karl\Cookies\karl@adtech[1].txt C:\Documents and Settings\Karl\Cookies\karl@adbrite[2].txt C:\Documents and Settings\Karl\Cookies\karl@3.adbrite[2].txt C:\Documents and Settings\Karl\Cookies\karl@bs.serving-sys[2].txt C:\Documents and Settings\Karl\Cookies\karl@drivecleaner[2].txt C:\Documents and Settings\Karl\Cookies\karl@statcounter[1].txt C:\Documents and Settings\Karl\Cookies\karl@doubleclick[1].txt C:\Documents and Settings\Karl\Cookies\karl@videoegg.adbureau[1].txt C:\Documents and Settings\Karl\Cookies\karl@revsci[2].txt C:\Documents and Settings\Karl\Cookies\karl@richmedia.yahoo[2].txt C:\Documents and Settings\Karl\Cookies\karl@questionmarket[1].txt C:\Documents and Settings\Karl\Cookies\karl@tradedoubler[2].txt C:\Documents and Settings\Karl\Cookies\karl@a[1].txt C:\Documents and Settings\Karl\Cookies\karl@tribalfusion[1].txt C:\Documents and Settings\Karl\Cookies\karl@ad.yieldmanager[2].txt C:\Documents and Settings\Karl\Cookies\karl@247realmedia[1].txt C:\Documents and Settings\Karl\Cookies\karl@hitbox[2].txt C:\Documents and Settings\Karl\Cookies\karl@casalemedia[2].txt C:\Documents and Settings\Karl\Cookies\karl@1071712319[1].txt C:\Documents and Settings\Karl\Cookies\karl@ehg-bskyb.hitbox[1].txt C:\Documents and Settings\Karl\Cookies\karl@fastclick[2].txt C:\Documents and Settings\Karl\Cookies\karl@2o7[2].txt C:\Documents and Settings\Karl\Cookies\karl@mediaplex[1].txt C:\Documents and Settings\Michael\Cookies\michael@anad.tacoda[1].txt C:\Documents and Settings\Michael\Cookies\michael@anat.tacoda[1].txt C:\Documents and Settings\Michael\Cookies\michael@smileycentral[1].txt Unclassified.SpywareBot (Not A Threat) HKU\S-1-5-21-1740818645-2308433262-3932484170-1006\Software\SpywareBot Trojan.Media-Codec/V3 HKCR\imageactivexobject.Chl HKCR\imageactivexobject.Chl\CLSID
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement". The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java. Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the "coffee cup" icon next to it.
Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions.
Reboot your computer once all Java components are removed
. Then from your desktop double-click on jre-1_6_2-windowsi586-p.exe to install the newest version.
Temporarily disable any of the following anti-spyware realtime protection programs that you may have Disable Realtime Protection or the fixes will not work. Be sure to turn yout anti-spyware programs back on once the computer is clean.
Turn off Norton's ScriptBlocking:
To disable Norton AntiVirus Script Blocking:
Start Norton AntiVirus. If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program. Click Options. If you see a menu, click Norton AntiVirus. In the left pane, click Script Blocking. In the right pane, uncheck Enable Script Blocking (recommended). Click OK.
Next, please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
Once in Safe Mode, open the "SmitfraudFix" folder again and double-click "smitfraudfix.cmd" Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing " Y " and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
The tool will now check if "wininet.dll " is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing "Y" and press "Enter".
The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply. The report can also be found at the root of the system drive, usually at C:\rapport.txt
Empty the restore folder. Go to start>control panel>system>system restore tab>check the box beside "turn off system restore>apply (takes a minute)>ok. Go back and uncheck the box to turn system restore back on>apply>ok.
Next, please reboot your computer in Safe Mode by doing the following :
Restart your computer
After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
Instead of Windows loading as normal, a menu with options should appear;
Select the first option, to run Windows in Safe Mode, then press "Enter".
Choose your usual account.
In safe mode navigate to and delete this folder if found:
C:\Program Files\Online Image Add-on
Run ATF-Cleaner from safe mode.Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button.
The information on Computing.Net is the opinions of its users. Such
opinions may not be accurate and they are to be used at your own risk.
Computing.Net cannot verify the validity of the statements made on this site. Computing.Net and Computing.Net, LLC hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.
PLEASE READ THE FULL DISCLAIMER AND LEGAL TERMS BY CLICKING HERE