WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
So there seems to be another issue.

I think the reason I can't change anything is because Task Manager also isn't working. When I Control Alt Delete, I get an error saying Task Manager has been disabled by the Administrator, yet I did nothing of the sort.

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Okay.
Delete the old look.bat because we have to do another look.bat to find that policy.

Oh yeah, I forgot about them policies.


  • Now open a new notepad file.
  • Input this into the notepad file:

    regedit /e peek1.txt "HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies"
    type peek1.txt >> look.txt
    del peek1.txt
    start notepad look.txt


  • Save this as look.bat, save it to your desktop.
  • Double click look.bat to run it.
  • Copy and paste the report back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Here you go:

Windows Registry Editor Version 5.00

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies]

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
"NoChangingWallpaper"=dword:00000001

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
"NoDriveTypeAutoRun"=dword:00000143
"CDRAutoRun"=dword:00000000
"NoDriveAutoRun"=dword:03ffffff
"NoSetActiveDesktop"=dword:00000001
"NoActiveDesktopChanges"=dword:00000001

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run]

[HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\system]
"DisableTaskMgr"=dword:00000001

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz

  • Now open a new notepad file.
  • Input this into the notepad file:

    Windows Registry Editor Version 5.00

    [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop]
    "NoChangingWallpaper"=-
    [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    "NoSetActiveDesktop"=-
    "NoActiveDesktopChanges"=-
    [HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Policies\system]
    "DisableTaskMgr"=-


  • Save this as fix.reg, save it to your desktop.
  • Double click fix.reg to run it.
  • Select yes to the registry merge prompt.


Again, may need to reboot for this to change.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Okay, so I did the above fixes, and still cannot use Task Manager or change my desktop's background =/

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Did you reboot after the reg fix?
Please post a new DDS log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Yep, I did reboot after both reg fixes.

Here is the DDS log:


DDS (Ver_09-01-07.01) - NTFSx86
Run by Rohit at 17:26:43.84 on Mon 01/12/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1374 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Rohit\Desktop\dds.com

============== Pseudo HJT Report ===============

uStart Page = www.google.com
uInternet Settings,ProxyOverride = *.local
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Catcher Class: {adecbed6-0366-4377-a739-e69dfba04663} - c:\program files\moyea\flv downloader\MoyeaCth.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: FlashFXP Helper for Internet Explorer: {e5a1691b-d188-4419-ad02-90002030b8ee} - c:\progra~1\flashfxp\IEFlash.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [Simp] c:\program files\secway\simplite-msn 2.2\SimpLite-MSN.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [MSKDetectorExe] c:\program files\mcafee\spamkiller\MSKDetct.exe /uninstall
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
uPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
uPolicies-system: DisableTaskMgr = 1 (0x1)
IE: Download linked FLV with GetFLV - c:\program files\getflv\iemenu\DownloadLinkFLV.htm
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Save with Download Manager... - file://c:\program files\j river\media center 11\DMDownload.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rohit\applic~1\mozilla\firefox\profiles\7qdh1rpk.default\
FF - prefs.js: browser.search.selectedEngine - Smogon
FF - prefs.js: browser.startup.homepage - hxxp://www.gamefaqs.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: network.proxy.http -
user_pref(network.proxy.http_port,);
FF - user.js: network.proxy.no_proxies_on -

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-12-6 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-12-6 26824]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2008-11-17 55024]
R3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\AmdTools.sys [2006-7-24 31744]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2008-11-17 7408]
R4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664]
R4 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2008-12-6 231704]
R4 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S0 zaxpahop;zaxpahop;c:\windows\system32\drivers\gumi.sys --> c:\windows\system32\drivers\gumi.sys [?]
S3 AlcrFilt;Alcor Micro Corp;c:\windows\system32\drivers\AlcrFilt.sys [2003-2-24 22860]
S3 gbalink;GBA Link Driver (gbalink.sys);c:\windows\system32\drivers\gbalink.sys [2007-1-6 19677]

=============== Created Last 30 ================

2009-01-05 08:26 --d----- c:\program files\Tracker Checker 2
2008-12-22 16:40 --d----- c:\docume~1\rohit\applic~1\Malwarebytes
2008-12-22 16:40 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-12-22 16:40 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-22 16:40 --d----- c:\program files\Malwarebytes' Anti-Malware
2008-12-22 16:40 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2008-12-20 17:10 --d----- c:\windows\system32\scripting
2008-12-20 17:10 --d----- c:\windows\l2schemas
2008-12-20 17:10 --d----- c:\windows\system32\en
2008-12-20 17:10 --d----- c:\windows\system32\bits
2008-12-20 17:07 --d----- c:\windows\ServicePackFiles
2008-12-20 16:08 6,066,176 ac------ c:\windows\system32\dllcache\ieframe.dll
2008-12-20 16:08 2,455,488 ac------ c:\windows\system32\dllcache\ieapfltr.dat
2008-12-20 16:08 991,232 ac------ c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-20 16:08 459,264 ac------ c:\windows\system32\dllcache\msfeeds.dll
2008-12-20 16:08 383,488 ac------ c:\windows\system32\dllcache\ieapfltr.dll
2008-12-20 16:08 267,776 ac------ c:\windows\system32\dllcache\iertutil.dll
2008-12-20 16:08 63,488 ac------ c:\windows\system32\dllcache\icardie.dll
2008-12-20 16:08 52,224 ac------ c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-20 16:08 13,824 ac------ c:\windows\system32\dllcache\ieudinit.exe
2008-12-20 16:04 --d----- c:\windows\network diagnostic
2008-12-20 16:03 33,792 ac------ c:\windows\system32\dllcache\custsat.dll

==================== Find3M ====================

2008-12-20 17:13 86,811 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-12-06 19:33 410,984 a------- c:\windows\system32\deploytk.dll
2008-12-06 14:58 10,520 a------- c:\windows\system32\avgrsstx.dll
2008-12-06 14:58 97,928 a------- c:\windows\system32\drivers\avgldx86.sys
2008-12-06 00:46 78,415 a------- c:\windows\system32\drivers\klif.cab
2008-10-23 07:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 15:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2008-08-17 18:52 47,360 a---h--- c:\docume~1\rohit\applic~1\pcouffin.sys
2006-09-10 10:52 81,920 a---h--- c:\docume~1\rohit\applic~1\ezpinst.exe

============= FINISH: 17:27:20.01 ===============

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Okay, lets try this now.

  • Now open a new notepad file.
  • Input this into the notepad file:

    Windows Registry Editor Version 5.00

    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer]


  • Save this as fix.reg, save it to your desktop.
  • Double click fix.reg to run it.
  • Select yes to the registry merge prompt.


Reboot and see if you can use Task Manager now.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Before I try your fix, I got task manager to work, by going into the Registry, under [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System], and changing a policy from 1 to 0.

However, I still cannot change desktop backgrounds, and it continues to stay this plain violet color. I will wait for your reply before doing anything else.

Edit: When I kill explorer.exe, I see my background. However when I rerun the process, this violet background comes up if that helps.

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Ah.
Try my fix anyway, it should remove all policies set by the malware.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Ok, so the task manager issue is solved, but this desktop issue still remains...
I don't really know what to do. If I see my background when I kill explorer.exe but not when its running, is that the issue?

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Hmm.
When you try to change the background picture, is it like the pictures are greyed out/locked?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Yeah, the pictures are locked out with a grayish color around them.

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Okay, try this:

Right click anywhere on the Desktop > Properties.
Click the "Desktop" tab, then hit the "Customize Desktop" button
This will open another windows, then open the "Web" tab.

If "My current homepage" is ticked, then untick it.

Any change now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
It was already unchecked.

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Ah, okay.
It may not be a registry item, it could be a group policy.
Press Start > Run
Type in:
gpedit.msc
Press enter.

Follow this path:
User Configuration->Administrative Templates->Control Panel->Display->Set "Prevent changing wallpaper" to disabled, or not configured.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Well, you sir are a genius. It was set by default to not configured, so I set it to disabled, and now I can change between desktop backgrounds. Thanks so much, its greatly appreciated!

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Glad I could help.

We need to make a new restore point.

To turn off System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (or the Turn off System Restore on all drives check box), and then click OK.
4. Click Yes when you receive the prompt to the turn off System Restore.

Now we need to make a new restore point.
To turn on System Restore, follow these steps:
1. Click Start, right-click My Computer, and then click Properties.
2. Click the System Restore tab.
3. Click the Turn off System Restore check box (To turn on System Restore), and then click OK.

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/
I also recommand the following add-ons for Firefox, they will help keep you safe from malicious scripts or activeX exploits.
https://addons.mozilla.org/en-US/firefox/addon/722
https://addons.mozilla.org/en-US/firefox/addon/1865
https://addons.mozilla.org/en-US/firefox/addon/433

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

To help you keep your software updated, please considering using this free software program that will check for program updates.
Update Checker

5) Finally, consider maintaining a firewall. Some good free firewalls are Kerio, or
Outpost
A tutorial on understanding and using firewalls may be found here.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. Big Grin

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
18 Trojans... - Page 1 DXwU4
18 Trojans... - Page 1 VvYDg

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

............................................................................................

Please be a GeekPolice fan on Facebook!

18 Trojans... - Page 1 Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

description18 Trojans... - Page 1 EmptyRe: 18 Trojans...

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum