bit worried about www.couldnotfind.com
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 




bit worried about www.couldnotfind.comExpand / Collapse
Author
Message
Posted 12/13/2003 1:09 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 1/22/2004 3:54 AM
Posts: 9, Visits: 1

Hi,


I am a bit worried about www.couldnotfind.com, there is probabely more as well


Logfile of HijackThis v1.97.7
Scan saved at 19:05:47, on 13/12/2003
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)


Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\unldrexe.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\windows\system32\win32gb.exe
C:\windows\system32\mscnt.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\atievxx.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Nicholas Yu.PIKACHU\Desktop\HijackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=132702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=132702
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132702
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://rd.yahoo.com/customize/ymsgr/defaults/sb/*http://www.yahoo.com/ext/search/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/
F1 - win.ini: run=c:\windows\system32\unldrexe.exe
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll (disabled by BHODemon)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll
O2 - BHO: OpinionBar IE monitor - {6607C683-AE7C-11D4-ACD7-0050DAC291A2} - C:\PROGRA~1\OPINIO~1\MyIEMonitor.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\ycomp5_0_2_4.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\PERFECT SERIES\The Complete Mouse List\4.0\lwb3dapp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Lexmark X5100 Series] "C:\Program Files\Lexmark X5100 Series\lxbabmgr.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [win32gb] c:\windows\system32\win32gb.exe /noconnect
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [31171816.exe] C:\WINDOWS\System32\31171816.exe
O4 - HKLM\..\Run: [99450320.exe] C:\WINDOWS\System32\99450320.exe
O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpySweeper] D:\NTLWebroot\Spy Sweeper\SpySweeper.exe /0
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: PersTray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O12 - Plugin for .png: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/bcd48c18cb7498/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/essentials/ymmapi_0727.dll
O16 - DPF: {A9FD89D6-C839-11D3-B0FE-0050044B8FE9} (OBInstallRunner Control) - http://www.opinionbar.com/download/resources/OBInstallCabinet.CAB
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/1d/player.virtools.com/downloads/player/Install2.1/Installer.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-32.cab


 



Nando
Post #7294
Posted 12/13/2003 1:09 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor

Group: Senior Advisor
Last Login: 12/4/2005 12:31 AM
Posts: 4,743, Visits: 5

Hi Nando, welcome.


 Yes, there is quite a bit more.

Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked. Make sure all browser and all Windows Explorer windows are closed before fixing.


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.couldnotfind.com/search_page.html?&account_id=132702
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.couldnotfind.com/search_page.html?&account_id=132702
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.couldnotfind.com/search_page.html?&account_id=132702
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/
F1 - win.ini: run=c:\windows\system32\unldrexe.exe
O2 - BHO: (no name) - {000006B1-19B5-414A-849F-2A3C64AE6939} - C:\WINDOWS\bi.dll (disabled by BHODemon)
O4 - HKLM\..\Run: [win32gb] c:\windows\system32\win32gb.exe /noconnect
O4 - HKLM\..\Run: [Mscnt] c:\windows\system32\mscnt.exe /noconnect
O4 - HKLM\..\Run: [Belt] C:\WINDOWS\Belt.exe
O4 - HKLM\..\Run: [31171816.exe] C:\WINDOWS\System32\31171816.exe
O4 - HKLM\..\Run: [99450320.exe] C:\WINDOWS\System32\99450320.exe
O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe

Reboot to safe mode and delete:
How to start your computer in safe mode


c:\windows\system32\win32gb.exe  <-- file
c:\windows\system32\mscnt.exe   <-- file
C:\WINDOWS\Belt.exe  <-- file
C:\WINDOWS\System32\31171816.exe  <-- file
C:\WINDOWS\System32\99450320.exe  <-- file

This next one seems funky and I cannot find much info on it.
c:\windows\system32\unldrexe.exe  <-- file
Could you please locate it, right click > sendto > compressed (zipped) folder and then mail it:
>>THIS MAIL ADDRESS<<
It may indeed be a new nasty. It would be appreciated.
Thank-You.

NOTE: To avoid the risk of any of the above not being found due to them having the 'Hidden' attribute, first make sure that in Folder Options > View hidden and operating system files are set to show:
How to Show Hidden/System Files
http://www.xtra.co.nz/help/0,,4155-1916458,00.html


Also:
Did you wittingly install OPINIONBAR ?


Download CWShredder:
http://www.spywareinfo.com/~merijn/files/cwshredder.zip
Unzip, run and hit the ->next tab to fix all found problems
Reboot.


Please post a fresh HJT log when done.
/



Cheers

Post #61546
Posted 12/13/2003 1:09 PM


New Member

New MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew MemberNew Member

Group: Forum Members
Last Login: 1/22/2004 3:54 AM
Posts: 9, Visits: 1

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/


Do I really need to check the above.


Start-Site.co.UK is the Portal I use and this is harmless. Let me know what you think and why I should get rid of this



Nando
Post #61547
Posted 12/13/2003 1:09 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor

Group: Senior Advisor
Last Login: 12/4/2005 12:31 AM
Posts: 4,743, Visits: 5
[QUOTE=Nando]

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.start-site.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.start-site.co.uk/


Do I really need to check the above.


Start-Site.co.UK is the Portal I use and this is harmless. Let me know what you think and why I should get rid of this


[/QUOTE]


Just leave them, or reset them when you open IE again.


.



Cheers

Post #61548
Posted 12/13/2003 1:09 PM


Senior Forum Advisor

Senior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum AdvisorSenior Forum Advisor

Group: Senior Advisor
Last Login: 12/4/2005 12:31 AM
Posts: 4,743, Visits: 5

 


F1 - win.ini: run=c:\windows\system32\unldrexe.exe
O4 - HKLM\..\Run: [Unldrexe] c:\windows\system32\unldrexe.exe

Downloader.Crypter.A virus found in attachment by AVG.



Cheers

Post #61549
« Prev Topic | Next Topic »


Reading This TopicExpand / Collapse

All times are GMT -6:00, Time now is 4:40pm

Powered By InstantForum.NET v4.1.4 © 2008
Execution: 0.094. 10 queries. Compression Enabled.