Plz help me wid ma comp

Discussion in 'System Security & Infection Support' started by basalganglia, Aug 23, 2008.

  1. basalganglia

    basalganglia

    Joined:
    Aug 23, 2008
    Messages:
    1
    Likes Received:
    0
    Location:
    India
    I got infected by some kinda trojan
    It was detected and removed by Avast!!!!!!
    But it came back on login.
    It disabled my taskmanager and startmenu.Finaly i had to change my startmenu to convert into classic mode and then from there i went to user accounts and created a new user,but now on bootup even de new user account shows to ave same trojan.This is my log file.Plz help me as of wat to do.Thanks in advance



    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.17184)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    E:\Program Files\Avast\aswUpdSv.exe
    E:\Program Files\Avast\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    E:\Program Files\BlueSoliel\BTNtService.exe
    E:\Nero 8.3\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\ZSSnp211.exe
    C:\WINDOWS\system32\IoctlSvc.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\system32\svchost.exe
    E:\Nero 8.3\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
    E:\PROGRA~1\Avast\ashDisp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
    E:\NOKIA PC SUITE\Nokia PC Suite 7\PCSuite.exe
    E:\Internet softwares\Internet Download Manager\IDMan.exe
    E:\Program Files\Avast\ashMaiSv.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    E:\Program Files\Avast\ashWebSv.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
    E:\Internet softwares\Internet Download Manager\IEMonitor.exe
    C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
    C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
    E:\Internet softwares\Yahoo!\Messenger\YahooMessenger.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O3 - Toolbar: rafbsvnx - {2F398AF7-F1A1-4D9E-92E9-36A94898D559} - C:\WINDOWS\rafbsvnx.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe
    O4 - HKLM\..\Run: [NBKeyScan] "E:\Nero 8.3\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\Avast\ashDisp.exe
    O4 - HKLM\..\Run: [b4535a9d] rundll32.exe "C:\WINDOWS\system32\nfwffgvi.dll",b
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O4 - HKCU\..\Run: [PC Suite Tray] "E:\NOKIA PC SUITE\Nokia PC Suite 7\PCSuite.exe" -onlytray
    O4 - HKCU\..\Run: [IDMan] E:\Internet softwares\Internet Download Manager\IDMan.exe /onboot
    O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "E:\NOKIA E 51\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "E:\NOKIA E 51\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: Download all links with IDM - E:\Internet softwares\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download FLV video content with IDM - E:\Internet softwares\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Download with IDM - E:\Internet softwares\Internet Download Manager\IEExt.htm
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O20 - AppInit_DLLs: cjokcy.dll ieblbz.dll
    O21 - SSODL: tsxngabr - {5D42201A-647A-4D46-A5D1-8AAD07A495EA} - C:\WINDOWS\tsxngabr.dll
    O21 - SSODL: vtqnxfko - {D93198FC-72D0-44A3-967C-6E98DA6BA9D7} - C:\WINDOWS\vtqnxfko.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Avast\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Avast\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Program Files\Avast\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - E:\Program Files\Avast\ashWebSv.exe
    O23 - Service: BlueSoleil Hid Service - Unknown owner - E:\Program Files\BlueSoliel\BTNtService.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - E:\Nero 8.3\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
     
    basalganglia, Aug 23, 2008
    #1
    1. Advertisements

  2. basalganglia

    Codex85 Mouse Potato VIP Member

    Joined:
    Apr 19, 2005
    Messages:
    776
    Likes Received:
    18
    Location:
    US
    Possibly nasty:
    O20 - AppInit_DLLs: cjokcy.dll ieblbz.dll
    O21 - SSODL: tsxngabr - {5D42201A-647A-4D46-A5D1-8AAD07A495EA} - C:\WINDOWS\tsxngabr.dll
    O21 - SSODL: vtqnxfko - {D93198FC-72D0-44A3-967C-6E98DA6BA9D7} - C:\WINDOWS\vtqnxfko.dll (file missing)

    Probably nasty:
    O3 - Toolbar: rafbsvnx - {2F398AF7-F1A1-4D9E-92E9-36A94898D559} - C:\WINDOWS\rafbsvnx.dll
    O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
     
    Codex85, Aug 24, 2008
    #2
    1. Advertisements

  3. basalganglia

    S Walch MAME 0.64 :) VIP Member

    Joined:
    Jun 2, 2003
    Messages:
    1,026
    Likes Received:
    14
    Location:
    Manchester
    Definitely nasty:

    O3 - Toolbar: rafbsvnx - {2F398AF7-F1A1-4D9E-92E9-36A94898D559} - C:\WINDOWS\rafbsvnx.dll

    O4 - HKLM\..\Run: [ZSSnp211] C:\WINDOWS\ZSSnp211.exe

    O4 - HKLM\..\Run: [b4535a9d] rundll32.exe "C:\WINDOWS\system32\nfwffgvi.dll",b

    O20 - AppInit_DLLs: cjokcy.dll ieblbz.dll

    O21 - SSODL: tsxngabr - {5D42201A-647A-4D46-A5D1-8AAD07A495EA} - C:\WINDOWS\tsxngabr.dll

    O21 - SSODL: vtqnxfko - {D93198FC-72D0-44A3-967C-6E98DA6BA9D7} - C:\WINDOWS\vtqnxfko.dll (file missing)

    O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm
     
    S Walch, Aug 25, 2008
    #3
  4. basalganglia

    Core in pounce mode Moderator

    Joined:
    Jun 30, 2003
    Messages:
    1,557
    Likes Received:
    24
    Location:
    Akaa, Finland
    Use AdAware from Safe Mode, and update XP to SP3.
     
    Core, Aug 25, 2008
    #4
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.