This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

HIJACKTHIS LOG - i really need help PLEASE HELP

16 min read

This thread's last reply is from February 7, 2008, 3:46 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hello and welcome to the forums

My name is Katana and I will be helping you to remove any infection(s) that you may have.

Please observe these rules while we work:
1. If you don't know, stop and ask! Don't keep going on.
2. Please reply to this thread. Do not start a new topic.
3. Please continue to respond until I give you the "All Clear"
(Just because you can't see a problem doesn't mean it isn't there)

If you can do those three things, everything should go smoothly :D

I apologize for the delay in responding, but as you can probably see the forums are quite busy
and sometimes a post manages to slip by us.
Unfortunately there are far more people needing help than there are helpers.



Download and Run ComboFix
  • Download Combofix from one of the links below :

    ComboFix.exe 1
    ComboFix.exe 2
    ComboFix.exe 3

  • You must download it to and run it from your Desktop
  • Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
  • Double click combofix.exe & follow the prompts.
  • When finished, it will produce a log. Please save that log to post in your next reply along with a fresh HJT log
  • Re-enable all the programs that were disabled during the running of ComboFix..


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
ComboFix SHOULD NOT be used unless requested by a forum helper
What Antivirus do you use ?

The following program/s are regarded as either "Rogue", being bundled with "Adware" or having dubious reputations

AdwareAlert << Used to be listed as Rogue
Spy Hunter << Used to be listed as Rogue
I recommend that you remove Via Add/Remove Programs

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

LimeWire

I'd like you to read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.

Also available here.

My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).
Please note: you must NOT use this whilst we are cleaning your machine.

Submit a File For Analysis
We need to have the files below Scanned by Uploading them/it to Virus Total

Please visit Virustotal
Copy/paste the the following file path into the window
C:\WINDOWS\04zt.sys
Click Submit/Send File
Please post back, to let me know the results.

Please do the same for the following files
C:\WINDOWS\system32\enb.exe
C:\WINDOWS\system32\jlx.exe
C:\WINDOWS\System32\NOWMEMDF.sys


If Virustotal is too busy please try Jotti



Download AVG Anti-Spyware
Please download AVG Anti-Spyware. to your Desktop or to your usual Download Folder.

  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.

If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.


Run AVG Anti-Spyware
Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Do not automatically generate reports
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.


Custom CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    DirLook::
    C:\Program Files\Peepop

    File::
    C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job
    C:\WINDOWS\04zt.sys
    C:\WINDOWS\system32\04zt.sys
    C:\WINDOWS\system32\34D562D718.sys
    C:\WINDOWS\system32\enb.exe
    C:\WINDOWS\system32\jlx.exe
    C:\WINDOWS\system\actualspystart.lnk
    C:\WINDOWS\wininit.ini
    C:\WINDOWS\system32\kbass1p.dll

    Driver::
    shpsv
    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9C0ADB68-353A-61DD-ED09-1D8003A6D1CB}]
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{9C0ADB68-353A-61DD-ED09-1D8003A6D1CB}"=-

  • Save this as CFScript.txt and place it on your desktop.





  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.


CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
That looks a bit better :), How are things running now ?




Kaspersky Online Scanner .
Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
Go Here http://www.kaspersky.com/kos/eng/partne ... bscan.html

Read the Requirements and limitations before you click Accept.
Allow the ActiveX download if necessary
Once the database has downloaded, click Next.
Click Scan Settings and change the "Scan using the following antivirus database" from standard to extended and then click OK.
Click on "My Computer" and then put the kettle on!
When the scan has completed, click Save Report As...
Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
"iija5onii" wrote:should i download Kaspersky Online Scanner?


Yes please
"katana" wrote:What Antivirus do you use ?

The following program/s are regarded as either "Rogue", being bundled with "Adware" or having dubious reputations

AdwareAlert << Used to be listed as Rogue
Spy Hunter << Used to be listed as Rogue
I recommend that you remove Via Add/Remove Programs


Did you remove these programs ?
What Antivirus do you use ?

Custom CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:



    File::
    C:\Documents and Settings\Jason\Desktop\Azureus_2.3.0.4_Win32.setup.exe
    C:\Program Files\Trend Micro\HijackThis\backups\backup-20071219-172335-917.dll
    C:\Program Files\Windows Media Player\wmplayer.exe.tmp
    Folder::
    Driver::
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "???TV??"=-
    "’CææôoTVûIïI"=-

  • Save this as CFScript.txt and place it on your desktop.





  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.


CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Did you used to have McAfee installed ?
If it is out of date, and you are not going to renew then I recommend that you remove it.

No Antivirus
I can see no indication of any Antivirus software.

Use an AntiVirus Software - It is very important that you have anti-virus software running on your machine.
This alone can save you a lot of trouble with malware in the future.
Free AV list
AVG Free
Avira AntiVir
Avast

Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week.
If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Antivirus is a MUST


Custom CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:


    Folder::
    C:\Documents and Settings\Jason\Application Data\AdwareAlert
    C:\Program Files\Enigma Software Group
    Driver::
    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "???TV??"=-
    "ÆC??¶oTV¹I´I"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpyHunter Security Suite"=-
    "MCUpdateExe"=-

  • Save this as CFScript.txt and place it on your desktop.





  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.


CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
There is no evidence of any keylogger in your logs ?


TotalScan
Your Antivirus and/or Antispyware may give a warning during the scan. This is perfectly normal
Please go to this site Link >> TotalScan << LINK
  • Under Scan Now click the Full Scan button
  • Follow the prompts to install the Active X if necessary
  • Go and make a cup of tea/coffee/beverage of your choice and watch some TV :)
  • When the scan is finished, a report will be generated
  • Next to Scan Details click the small Save button and save the report to your desktop.
  • Please post the report in your reply.


For the next scan please close all the programs that you can, and do not use the machine while it is running.
Please Download GMER to your desktop

Please create a folder in the Program Files folder called GMER.

Download GMER and extract it to the C:\program files\GMER folder you have just made.


Run the Gmer.exe program by double-clicking the executable file gmer.exe.
You may be prompted to scan immediately if GMER detects rootkit activity.

If you are prompted to scan your system click "yes" to begin the scan.
If you are not prompted, Click the "Rootkit" tab, then click "Scan".


DO NOT touch the PC at ALL for Whatever reason/s until it has 100% completed its scan, or attempted scan in case of some error etc !

At the end of the scan, click "Copy" to copy the scan results to the clipboard. Then paste the results in a notepad file and also paste them back in your next reply.

Please post the results from the GMER scan in your reply.
Do you know what aefdisk32v11 is ?

Custom CFScript
  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:



    File::
    c:\windows\system32\winupdt.bin
    c:\windows\system32\winupdt.008
    c:\windows\system32\log.~
    c:\windows\system32\key.~
    C:\WINDOWS\Downloaded Program Files\s4initialsetup1.0.0.7.inf
    c:\windows\searchen.dat

    Registry::
    [-hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\savenow]
    [-hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\abi-1]
    [-hkey_classes_root\install.install.1]
    [-hkey_classes_root\install.install]
    [-hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\yoursitebar]
    [-hkey_local_machine\software\microsoft\windows\currentversion\app management\arpcache\power scan]
    [-hkey_classes_root\clsid\{84564147-251a-4f06-8fc5-8ae36b3a55ab}]
    [-hkey_classes_root\clsid\{17b8b110-fd82-4a50-9a46-328bb50c6ca4}]
    [-hkey_local_machine\software\ndwserv030105]
    [-hkey_LOCAL_MACHINE\software\classes\CLSID\{17B8B110-FD82-4A50-9A46-328BB50C6CA4}]
    [-hkey_LOCAL_MACHINE\software\classes\CLSID\{84564147-251A-4F06-8FC5-8AE36B3A55AB}]

  • Save this as CFScript.txt and place it on your desktop.





  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.


CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

=========================================================================================
These following tools will produce Very Big logs, create a folder on your desktop and put all the logs into it.
When you have finished all the scans Right-Click the folder and select Send to >> Compressed folder please attach the compressed folder to your reply
=========================================================================================
Download and Run SR Engineer
Please download SREng.
  • Extract it to your desktop.
  • Double click SREng.exe to run it.
  • Select Smart Scan and tick Verify Digital Signatures.
  • Click on the Scan button.
  • When finished click on the Save Reports button and save the log to your desktop.



GetSystemInfo

Please download GetSystemInfo from HERE
Double click GetSysteminfo.exe
It will ask you where to save the report, please save it to your desktop or somewhere that you can find it easily.
It will display it's progress on your screen, when the box disappears it has finished.


Eset NOD32 Online AntiVirus

Run Eset NOD32 Online AntiVirus
http://www.eset.eu/online-scanner
Note: You will need to use Internet Explorer for this scan.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your current Antivirus software. You can usually do this with its Notfication Tray icon near the clock.
  • Click Start
  • Make sure that the option "Remove found threats" is Un-checked, and the option "Scan unwanted applications" is checked
  • Click Scan
  • Wait for the scan to finish
  • Re-enable your Anvirisus software.
  • A logfile is created and located at C:\\Program Files\\EsetOnlineScanner\\log.txt. Please include this on your post.


Logs/Information to Post in Reply
Please post the following logs/Information in your reply
  • ComboFix Log >> Please post this as normal
      Put the following in the folder
    • SREng Log
    • Nod 32 Log
    • GetSystemInfo Log
Please download a fresh copy and then run the CFScript
Download Combofix from one of the links below :

ComboFix.exe 1
ComboFix.exe 2
ComboFix.exe 3
These following tools will produce Very Big logs, create a folder on your desktop and put all the logs into it.
When you have finished all the scans Right-Click the folder and select Send to >> Compressed folder.
Please attach the compressed folder.zip to your reply
Due to the size of the logs, I have requested a second set of eyes to make sure I don't miss anything.
Please be patient, I will be back ASAP.
I do apologize for the delay, I haven't forgotten about you.
The logs you posted are being checked very carefully, as we can't find any cause for the problem at the moment.
We can find no evidence of malware on your machine :(
How do you change the passwords on the site ?
do you receive an e-mail with the new password ?
Right, just so I am clear on what is happening ....

You try to log on to the site, and find that the password has been changed.
You request a new password via e-mail, and everything is fine for a while.
Then the password gets changed again ?
I would suggest creating a new E-mail address and getting the password sent to that.
Given that your logs show no sign of infection I can only guess that either your e-mail password is known, and someone is reading the new passwords OR the game server itself has been hacked.

There is no evidence of keyloggers or rootkits in your logs.

The only other possibility is that someone who has physical access to the machine is doing it.