start/system tray tool bar

CastleCops -> Trend Micro HijackThis Logs

Author: 24giovanniLocation: USA PostPosted: Sun Jun 29, 2008 12:09 am    Post subject: start/system tray tool bar

Hi, My start/system tray tool bar is twice the width that it should be. I am not sure how it got that way but how do I fix this? Also, Every time I boot up my computer it says automatic updates is turned off even after I restart it. Any ideas what's causing this? If so, what do I need to do? I am running sbybot s & d now.

thx

Author: CudniLocation: Et In Arcadia ego PostPosted: Sun Jun 29, 2008 12:16 am    Post subject:

hover over the upper edge of the toolbar until cursor changes to arrows pointing up and down then hold the left mouse down and resize. If nothing happens when you hover over, right click on toolbar and deselect Lock the taskbar. Did you set the autoupdates on automatic in Services?

Author: 24giovanniLocation: USA PostPosted: Sun Jun 29, 2008 12:48 am    Post subject:

Cudni wrote:
hover over the upper edge of the toolbar until cursor changes to arrows pointing up and down then hold the left mouse down and resize. If nothing happens when you hover over, right click on toolbar and deselect Lock the taskbar. Did you set the autoupdates on automatic in Services?


I got hit with the virtumonde virus. I would that be causing these things to happen?

Also, I am using adaware 2008 to get rid of it. Is there anything else i NEED TO DO TOO?

thx

Author: CudniLocation: Et In Arcadia ego PostPosted: Sun Jun 29, 2008 12:52 am    Post subject:

use more tools and post in hjt forum if still having probs
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Overview

Cudni

Author: 24giovanniLocation: USA PostPosted: Sun Jun 29, 2008 2:27 am    Post subject:

Cudni, I am in question on what it says to do on the vundo HJT log. I don't know which ones that want to put in the white box on the "02 BHO and 020 WinLogon ". Do they want me to put in the bolded ones?

Logfile of HijackThis v1.99.1
Scan saved at 9:45:04 PM, on 6/28/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\IoctlSvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SPAMfighter\sfus.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\DNA\btdna.exe
C:\Documents and Settings\me.MOE.000\Desktop\UltraSurf 8.9.exe
C:\Program Files\Solways Task Scheduler\tasksched.exe
C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R3 - URLSearchHook: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: (no name) - {D554A583-D4CF-4A6F-B07A-CB25F60FA743} - C:\WINDOWS\system32\hgGyvtSi.dll
O2 - BHO: (no name) - {DADCCFE7-103D-4566-9260-5C3806C2EE1B} - C:\WINDOWS\system32\wvULDWPf.dll (file missing)
O3 - Toolbar: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
O3 - Toolbar: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [dcb59a0d] rundll32.exe "C:\WINDOWS\system32\ljnacosx.dll",b
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msltstsoft_updt.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA9978] command /c del "C:\WINDOWS\system32\wvULDWPf.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9722] cmd /c del "C:\WINDOWS\system32\wvULDWPf.dll_old"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - Startup: Shortcut to UltraSurf 8.9.exe.lnk = C:\Documents and Settings\me.MOE.000\Desktop\UltraSurf 8.9.exe
O4 - Startup: Solway's Task Scheduler.lnk = C:\Program Files\Solways Task Scheduler\tasksched.exe
O4 - Startup: SUPERAntiSpyware Free Edition.lnk = C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll C:\PROGRA~1\Comodo\Css\cssdll32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: hgGyvtSi - C:\WINDOWS\SYSTEM32\hgGyvtSi.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SPAMfighter Update Service - SPAMfighter ApS - C:\Program Files\SPAMfighter\sfus.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe

Author: Mister2 PostPosted: Sun Jun 29, 2008 4:54 am    Post subject:

Moved to appropriate forum

Author: 24giovanniLocation: USA PostPosted: Sun Jun 29, 2008 4:31 pm    Post subject:

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: TorrentMan Toolbar - {7c5c0f58-e061-457d-9033-77307f5ed00c} - C:\Program Files\TorrentMan\tbTorr.dll
O2 - BHO: (no name) - {D554A583-D4CF-4A6F-B07A-CB25F60FA743} - C:\WINDOWS\system32\hgGyvtSi.dll
O2 - BHO: (no name) - {DADCCFE7-103D-4566-9260-5C3806C2EE1B} - C:\WINDOWS\system32\wvULDWPf.dll (file missing)

and

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: hgGyvtSi - C:\WINDOWS\SYSTEM32\hgGyvtSi.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll


Are these the things I need to enter in the white box? Can someone please help me with this? I tried copy and paste but I can not paste entries in white box? How do I do it, please?

Author: 24giovanniLocation: USA PostPosted: Sun Jun 29, 2008 10:21 pm    Post subject:

Someone please let me know when I can get help with this.

Author: Prince_Serendip PostPosted: Mon Jun 30, 2008 2:39 pm    Post subject:

Your version of HijackThis is out-of-date. Please uninstall your old copy of HJT with Add/Remove Programs.

Please follow the instructions >>>HERE<<< at #5. Thanks.

Note: The current version is HijackThis 2.0.2.


Update HijackThis first, then proceed with the following:

Please remove BitTorrent DNA using the instructions below. We do not clean logs that have P2P applications installed as this can cause reinfection during your cleaning.

Please refer to this topic:
CastleCops Link/t204179-P2P_programs_we_ask_that_you_remove_first.html
(Don't put it back until after your cleaning is completed.)


P2P apps must be completely removed before we will help you.


Some P2P applications are as bad as trojans when it comes to removal. Here's what you do:

Check Add/Remove Programs again via Control Panel. If any BitTorrent DNA entry is still there, remove it.


Next...
Windows XP: If it's not in Add/Remove Programs, open Task Manager by right-clicking your desktop taskbar and selecting it. Choose the Processes tab. Look for the btdna.exe executable file. Highlight it by clicking on it once, then click the End Process button on the bottom right. You'll get a warning box but just turn it off anyway. Close Task Manager.


Run HijackThis. Do a System Scan Only. Put a checkmark beside this entry only, be sure all other windows are closed, then click the Fix Checked button.

O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"

Reboot your computer.

Next, do a system scan and save a logfile with HijackThis. Post the new log here.



CastleCops -> Trend Micro HijackThis Logs

All times are GMT

Page 1 of 1


Powered by phpBB © 2001 phpBB Group