1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Popup error messages and new icons appearing on desktop - HTJ log attached

Discussion in 'Virus & Other Malware Removal' started by savo, Mar 27, 2008.

Thread Status:
Not open for further replies.
  1. savo

    savo Thread Starter

    Joined:
    Mar 27, 2008
    Messages:
    4
    Hello,

    I am hoping you may be able to help. I have a PC that has got a number of new icons appearing on the desktop ("Spyware&MalwareProtector", "Privacy Protector", and "Error Cleaner"). The desktop has also changed to a red background with a hazard symbol with the words 'your pc is in danger' on it.

    I have read a few other posts on this topic but the ones I read stated not to delete certain files as those fixes were tailored only for that particular PC. I have therefore run Hijack This on the PC and attach a copy of the log file below. I would be very grateful if anybody could help me work out what needs to be done to remove the malware etc.

    Regards,

    Savo

    ---

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:37:29, on 27/03/2008
    Platform: Windows 2000 SP2 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\csrss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Canon\DIAS\CnxDIAS.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
    C:\Program Files\CA\eTrust\InoculateIT\InoRT.exe
    C:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
    C:\WINNT\LogWatNT.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\vsAOD.Exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\rc\winvnc.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\atiptaxx.exe
    C:\Program Files\CA\eTrust\InoculateIT\realmon.exe
    C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
    C:\WINNT\System32\internat.exe
    C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
    C:\Program Files\Internet Explorer\Connection Wizard\ICWCONN1.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\System32\ntos.exe,
    O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
    O2 - BHO: RDL Rolex - {4A7A1FA6-EA33-48B7-AC8C-8E036244F665} - C:\WINNT\drnpfdxrfs.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: etlrlws - {A40201E7-01E9-4243-B425-DFCA3DECF177} - C:\WINNT\TEMP\ac8zt2\etlrlws.dll (file missing)
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
    O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrust\InoculateIT\realmon.exe"
    O4 - HKLM\..\Run: [WinVNC] "C:\WINNT\system32\rc\winvnc.exe" -servicehelper
    O4 - HKLM\..\Run: [PN] "C:\Program Files\Citrix\ICA Client\pn.exe"
    O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
    O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    O4 - HKLM\..\Run: [WheelMouse] C:\PROGRA~1\A4Tech\Mouse\Amoumain.exe
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Picture Package Menu.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
    O4 - Global Startup: Picture Package VCD Maker.lnk = C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O14 - IERESET.INF: START_PAGE_URL=http://www.google.com
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1171285353183
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = gwi.co.uk
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = gwi.co.uk
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = gwi.co.uk
    O21 - SSODL: bokpkov - {21946511-501D-495A-BDFE-B5C0F54C04FE} - C:\WINNT\bokpkov.dll
    O21 - SSODL: altvxvm - {5A673E9D-46D1-4487-A7A4-718CDAE88677} - C:\WINNT\altvxvm.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
    O23 - Service: Canon Driver Information Assist Service - CANON INC. - C:\Program Files\Canon\DIAS\CnxDIAS.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: eTrust InoculateIT RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\InoculateIT\InoRpc.exe
    O23 - Service: eTrust InoculateIT Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\InoculateIT\InoRT.exe
    O23 - Service: eTrust InoculateIT Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\InoculateIT\InoTask.exe
    O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINNT\LogWatNT.exe
    O23 - Service: Visionsoft Audit On Demand Service (vsAOD) - Visionsoft Limited - C:\WINNT\vsAOD.Exe
    O23 - Service: VNC (WinVNC) - AT&T Research Labs Cambridge - C:\WINNT\system32\rc\winvnc.exe

    --
    End of file - 5764 bytes
     
  2. savo

    savo Thread Starter

    Joined:
    Mar 27, 2008
    Messages:
    4
    Hi,

    I was just wondering if anyone has any ideas on what needs to be done to fix the above problem please? I'm a bit stumped and need to try to get the PC back up and running again asap.

    Thanks,

    Savo
     
  3. savo

    savo Thread Starter

    Joined:
    Mar 27, 2008
    Messages:
    4
    Sorry to keep asking but I'm really struggling with trying to understand what to do with this Hijackthis log and would be really grateful if somebody could shed some light on the subject.

    Thanks guys,

    Ian
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/697575

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice