GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

Win32/Cryptor Hijackthis Log included

View previous topic View next topic Go down

Win32/Cryptor Hijackthis Log included

Post by Phicol on Mon May 11, 2009 3:11 pm

AVG 8.5.323 is picking up Cryptor, IE is totally broken can only surf on Safari at the moment. IE redirects if you don't directly go to a site, if you click any link it redirects or closes the browser.

This is the log from AVG:

"\\?\globalroot\systemroot\system32\UACdfqhsrnh.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"\\?\globalroot\systemroot\system32\UACdfqhsrnh.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"\\?\globalroot\systemroot\system32\UACdfqhsrnh.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"\\?\globalroot\systemroot\system32\UACwpbutont.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"\\?\globalroot\systemroot\system32\UACwpbutont.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"\\?\globalroot\systemroot\system32\UACwpbutont.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"\\?\globalroot\systemroot\system32\UACwpbutont.dll";"Virus identified Win32/Cryptor";"Moved to Virus Vault"
"C:\WINDOWS\explorer.exe (2208)";"Virus identified Win32/Cryptor";""
"C:\WINDOWS\system32\svchost.exe (1256)";"Virus identified Win32/Cryptor";""
"C:\WINDOWS\system32\svchost.exe (1492)";"Virus identified Win32/Cryptor";""
"C:\WINDOWS\system32\svchost.exe (2740)";"Virus identified Win32/Cryptor";""

This is the log from hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:02:25 AM, on 5/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Safari\Safari.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\DOCUME~1\NCD67~1.CRO\LOCALS~1\Temp\SafA1.tmp\hijackgpthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = [You must be registered and logged in to see this link.]
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {39F9634C-EFF0-4983-BC97-F53542BE4156} - C:\WINDOWS\system32\ljJCuUNd.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {495945B7-CC8A-452E-B16E-E9272CDD96A0} - C:\WINDOWS\system32\rqRJaxxu.dll (file missing)
O2 - BHO: (no name) - {5FB13B24-D3B6-426A-879F-8175AEF038A4} - C:\WINDOWS\system32\iiffGxYp.dll (file missing)
O2 - BHO: (no name) - {6E60D48B-17C4-4677-9775-66E81E324AAA} - C:\WINDOWS\system32\khffeeEw.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {9128E7CE-F882-4797-8BFA-0E3BE765B24B} - C:\WINDOWS\system32\urqRKBTM.dll (file missing)
O2 - BHO: BHO - {ABD45510-9B22-41cd-9ACD-8182A2DA7C63} - C:\WINDOWS\system32\iehelper.dll (file missing)
O2 - BHO: (no name) - {AD957B9E-D63F-4539-9BD4-E4AE38BB62EB} - C:\WINDOWS\system32\ddcYrOIX.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: (no name) - {C0BA9AF1-325E-45E1-AA8B-5A046A59F769} - C:\WINDOWS\system32\jkKbxWmn.dll (file missing)
O2 - BHO: (no name) - {C97BBE7B-AB86-4EFA-A99F-BFBEDB5AF7BD} - C:\WINDOWS\system32\vtUkjJYR.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: (no name) - {E24D3F79-17B1-4820-AF68-3BBED59E43D5} - C:\WINDOWS\system32\jkkIAQKB.dll (file missing)
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [regcmdcons] c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
O4 - HKLM\..\Run: [AutoTBar] c:\Program Files\HP\Digital Imaging\bin\AUTOTBAR.EXE
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: &Google Search - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: Similar Pages - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - [You must be registered and logged in to see this link.] Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} - [You must be registered and logged in to see this link.]
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - [You must be registered and logged in to see this link.]
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {E5168F0C-8591-11D4-BCDF-006008B7FEA4} (PWLNINST Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetup Control) - [You must be registered and logged in to see this link.]
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: urqNFyYR - urqNFyYR.dll (file missing)
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe

--
End of file - 11674 bytes

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Mon May 11, 2009 3:13 pm

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {39F9634C-EFF0-4983-BC97-F53542BE4156} - C:\WINDOWS\system32\ljJCuUNd.dll (file missing)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: (no name) - {495945B7-CC8A-452E-B16E-E9272CDD96A0} - C:\WINDOWS\system32\rqRJaxxu.dll (file missing)
    O2 - BHO: (no name) - {5FB13B24-D3B6-426A-879F-8175AEF038A4} - C:\WINDOWS\system32\iiffGxYp.dll (file missing)
    O2 - BHO: (no name) - {6E60D48B-17C4-4677-9775-66E81E324AAA} - C:\WINDOWS\system32\khffeeEw.dll (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {9128E7CE-F882-4797-8BFA-0E3BE765B24B} - C:\WINDOWS\system32\urqRKBTM.dll (file missing)
    O2 - BHO: BHO - {ABD45510-9B22-41cd-9ACD-8182A2DA7C63} - C:\WINDOWS\system32\iehelper.dll (file missing)
    O2 - BHO: (no name) - {AD957B9E-D63F-4539-9BD4-E4AE38BB62EB} - C:\WINDOWS\system32\ddcYrOIX.dll (file missing)
    O2 - BHO: (no name) - {C0BA9AF1-325E-45E1-AA8B-5A046A59F769} - C:\WINDOWS\system32\jkKbxWmn.dll (file missing)
    O2 - BHO: (no name) - {C97BBE7B-AB86-4EFA-A99F-BFBEDB5AF7BD} - C:\WINDOWS\system32\vtUkjJYR.dll (file missing)
    O2 - BHO: (no name) - {E24D3F79-17B1-4820-AF68-3BBED59E43D5} - C:\WINDOWS\system32\jkkIAQKB.dll (file missing)
    O20 - Winlogon Notify: urqNFyYR - urqNFyYR.dll (file missing)


  • Press "Fix Checked"
  • Close Hijack This.

1. Please download The Avenger by Swandog46 to your Desktop
Link: [You must be registered and logged in to see this link.] or [You must be registered and logged in to see this link.].

  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop

Note: This tool was posted specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, start The Avenger program by clicking on its icon on your desktop.

  • Leave the script box empty.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
3. Please copy/paste the content of c:\avenger.txt into your reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Mon May 11, 2009 4:56 pm

Ran Hijackthis and removed those keys, then downloaded avenger and followed the instructions. It restarted the computer and blue screened, did a memory dump. Only way to get it back was to go to a last known good config. Also upon the second reboot AVG freaked out and found a ton of new infections:

"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:45:05 AM";"file";"C:\WINDOWS\system32\WgaTray.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:45:05 AM";"file";"C:\WINDOWS\system32\WgaTray.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:45:05 AM";"file";"C:\WINDOWS\system32\WgaTray.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:45:00 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:45:00 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:45:00 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\Program Files\AVG\AVG8\avgcsrvx.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\Program Files\AVG\AVG8\avgcsrvx.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\Program Files\AVG\AVG8\avgcsrvx.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:59 AM";"file";"C:\Program Files\AVG\AVG8\avgcsrvx.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:58 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:58 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:58 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:57 AM";"file";"C:\WINDOWS\system32\HPZipm12.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:52 AM";"file";"C:\WINDOWS\system32\alg.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:52 AM";"file";"C:\WINDOWS\system32\alg.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:52 AM";"file";"C:\WINDOWS\system32\alg.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:52 AM";"file";"C:\WINDOWS\system32\alg.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:51 AM";"file";"C:\Program Files\iPod\bin\iPodService.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:51 AM";"file";"C:\Program Files\iPod\bin\iPodService.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:50 AM";"file";"C:\Program Files\iPod\bin\iPodService.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:50 AM";"file";"C:\Program Files\iPod\bin\iPodService.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\dllhost.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\dllhost.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\dllhost.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:48 AM";"file";"C:\WINDOWS\system32\dllhost.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:47 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:47 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:47 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:47 AM";"file";"C:\WINDOWS\system32\regsvr32.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACdfqhsrnh.dll";"Infected";"5/11/2009, 11:44:47 AM";"file";"C:\WINDOWS\system32\imapi.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACwpbutont.dll";"Infected";"5/11/2009, 11:44:46 AM";"file";"C:\WINDOWS\system32\imapi.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UAClygeabgr.dll";"Infected";"5/11/2009, 11:44:46 AM";"file";"C:\WINDOWS\system32\imapi.exe"
"Virus identified Win32/Cryptor";"C:\WINDOWS\system32\UACbvcxbjvw.dll";"Infected";"5/11/2009, 11:44:46 AM";"file";"C:\WINDOWS\system32\imapi.exe"
goes on and on

I tried this twice. Here is the log from Avenger:

Logfile of The Avenger Version 2.0, (c) by Swandog46
[You must be registered and logged in to see this link.]

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "UACd.sys" found!
ImagePath: \systemroot\system32\drivers\UACdlvtkcpa.sys
Driver disabled successfully.

Rootkit scan completed.


Completed script processing.

*******************

Finished! Terminate.

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Mon May 11, 2009 4:59 pm

1. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+CCrying


Drivers to delete:
UACd.sys

Files to delete:
C:\WINDOWS\system32\drivers\UACdlvtkcpa.sys

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


2. Now, start The Avenger program by clicking on its icon on your desktop.

  • Under "Input script here:", paste in the script from the quote box above.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
3. Please copy/paste the content of c:\avenger.txt into your reply.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Mon May 11, 2009 5:14 pm

I copied and pasted the script in Avenger, it rebooted. It blue screened twice, on the third reboot in came into windows and showed this log:

Logfile of The Avenger Version 2.0, (c) by Swandog46
[You must be registered and logged in to see this link.]

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Driver "UACd.sys" deleted successfully.
File "C:\WINDOWS\system32\drivers\UACdlvtkcpa.sys" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Mon May 11, 2009 5:30 pm

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Tue May 12, 2009 4:58 pm

It looks good so far, running an AVG scan. Computer is looking normal but will wait to hear from you on the next step if any.

MBAM log:

Malwarebytes' Anti-Malware 1.36
Database version: 2109
Windows 5.1.2600 Service Pack 3

5/12/2009 10:47:25 AM
mbam-log-2009-05-12 (10-47-25).txt

Scan type: Quick Scan
Objects scanned: 128328
Time elapsed: 29 minute(s), 31 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\\toolbar.tb (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\\toolbar.tb.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\\Interface\\{3c1a06cc-3981-4db9-b5b6-b4b8ecb1d7f2} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Ext\\Stats\\{abd45510-9b22-41cd-9acd-8182a2da7c63} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Code Store Database\\Distribution Units\\{288c5f13-7e52-4ada-a32e-f5bf9d125f99} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\\SOFTWARE\\UAC (Rootkit.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\\Documents and Settings\\All Users\\Application Data\\N1 (Rogue.AntiVirus1) -> Quarantined and deleted successfully.

Files Infected:
C:\\WINDOWS\\system32\\uacinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\\WINDOWS\\Temp\\cd16fb79-2a8b-4102-884b-70640d773867.tmp (Heuristics.Malware) -> Quarantined and deleted successfully.
C:\\WINDOWS\\system32\\UACmujbfkkj.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\\WINDOWS\\system32\\UACnktvxdqi.log (Trojan.Agent) -> Quarantined and deleted successfully.

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Tue May 12, 2009 5:03 pm

Hello.
One more scan to do, but it's hard to post because forumotion software is having problems right now, so I can't post anything with BBcode in it.

Please stand by.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Tue May 12, 2009 5:50 pm

AVG Scan results:

"Scan ""Scan whole computer"" was finished."
"No infection was found during this scan"
"Folders selected for scanning:";"Scan whole computer"
"Scan started:";"Tuesday, May 12, 2009, 10:57:38 AM"
"Scan finished:";"Tuesday, May 12, 2009, 12:29:04 PM (1 hour(s) 31 minute(s) 26 second(s))"
"Total object scanned:";"817070"
"User who launched the scan:";"n.crocker"

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Wed May 13, 2009 11:55 am


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Wed May 13, 2009 1:06 pm

DDS Log:

DDS (Ver_09-03-16.01) - NTFSx86
Run by n.crocker at 8:03:03.44 on Wed 05/13/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.394 [GMT -5:00]

AV: AVG Internet Security *On-access scanning enabled* (Updated)
FW: AVG Firewall *disabled*

============== Running Processes ===============

C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\iTunes\iTunesHelper.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Safari\Safari.exe
C:\Documents and Settings\n.crocker\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uSearch Page = [You must be registered and logged in to see this link.]
uSearch Bar = [You must be registered and logged in to see this link.]
uDefault_Search_URL = [You must be registered and logged in to see this link.]
uSearchMigratedDefaultURL = [You must be registered and logged in to see this link.]
mDefault_Search_URL = [You must be registered and logged in to see this link.]
mSearch Page = [You must be registered and logged in to see this link.]
mStart Page = [You must be registered and logged in to see this link.]
mSearch Bar = [You must be registered and logged in to see this link.]
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
mSearchAssistant = [You must be registered and logged in to see this link.]
mURLSearchHooks: H - No File
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - No File
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [regcmdcons] c:\hp\bin\cloaker.exe c:\hp\bin\cmdcons.cmd
mRun: [AutoTBar] c:\program files\hp\digital imaging\bin\AUTOTBAR.EXE
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [PS2] c:\windows\system32\ps2.exe
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [AcronisTimounterMonitor] c:\program files\acronis\trueimagehome\TimounterMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
IE: &Google Search - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000
IE: Similar Pages - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - c:\program files\google\GoogleToolbar1.dll/cmtrans.html
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - [You must be registered and logged in to see this link.]
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - [You must be registered and logged in to see this link.]
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - [You must be registered and logged in to see this link.]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} - [You must be registered and logged in to see this link.]
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - [You must be registered and logged in to see this link.]
DPF: {E5168F0C-8591-11D4-BCDF-006008B7FEA4} - [You must be registered and logged in to see this link.]
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - [You must be registered and logged in to see this link.]
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, digeste.dll
LSA: Authentication Packages = msv1_0 nwprovau c:\windows\system32\ljJCuUNd relog_ap

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\ncd67~1.cro\applic~1\mozilla\firefox\profiles\y7cfs61a.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npipcd3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npiPLATO_22.dll
FF - plugin: c:\program files\real\realarcade\plugins\mozilla\npracplug.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

============= SERVICES / DRIVERS ===============

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2008-10-14 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-14 325896]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-14 27784]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2008-10-14 108552]
R1 NEOFLTR_520_9469;Juniper Networks TDI Filter Driver (NEOFLTR_520_9469);c:\windows\system32\drivers\NEOFLTR_520_9469.sys [2005-11-9 57062]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-7 298776]
R2 avgfws8;AVG8 Firewall;c:\progra~1\avg\avg8\avgfws8.exe [2009-4-24 1366904]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2008-10-14 29208]
R3 CXFALCON;Conexant Falcon II NTSC Video Capture;c:\windows\system32\drivers\cxfalcon.sys [2005-5-30 85248]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2008-10-14 29208]
S3 CCCP106;CIF USB Camera (2110A);c:\windows\system32\drivers\cccp106.sys [2005-9-5 227200]

=============== Created Last 30 ================

2009-05-11 13:06 --d----- c:\docume~1\ncd67~1.cro\applic~1\Malwarebytes
2009-05-11 13:06 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-11 13:06 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-11 13:06 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-05-11 13:06 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-05-11 11:28 61,440 a------- c:\windows\system32\drivers\fdzyjs.sys
2009-05-11 09:58 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-06 08:52 441,760 a------- c:\windows\system32\drivers\timntr.sys
2009-05-06 08:52 44,384 a------- c:\windows\system32\drivers\tifsfilt.sys
2009-05-06 08:52 129,248 a------- c:\windows\system32\drivers\snapman.sys
2009-05-06 08:52 368,544 a------- c:\windows\system32\drivers\tdrpman.sys
2009-05-01 15:43 18 a---h--- C:\SYSREST
2009-05-01 11:29 --d----- c:\documents and settings\n.crocker\WINDOWS
2009-05-01 11:29 --d----- c:\docume~1\ncd67~1.cro\applic~1\Symantec
2009-05-01 11:29 --d----- c:\docume~1\ncd67~1.cro\applic~1\Juniper Networks
2009-05-01 11:29 --d----- c:\documents and settings\n.crocker
2009-05-01 11:24 --d----- c:\windows\system32\NtmsData
2009-04-23 22:59 552 a------- c:\windows\system32\d3d8caps.dat
2009-04-23 16:21 --d----- c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-04-18 21:27 65,156 a---h--- c:\windows\system32\mlfcache.dat
2009-04-15 16:43 401,408 -------- c:\windows\system32\dllcache\rpcss.dll
2009-04-15 16:43 284,160 -------- c:\windows\system32\dllcache\pdh.dll
2009-04-15 16:43 473,600 -------- c:\windows\system32\dllcache\fastprox.dll
2009-04-15 16:43 227,840 -------- c:\windows\system32\dllcache\wmiprvse.exe
2009-04-15 16:43 110,592 -------- c:\windows\system32\dllcache\services.exe
2009-04-15 16:43 729,088 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-04-15 16:43 714,752 -------- c:\windows\system32\dllcache\ntdll.dll
2009-04-15 16:43 617,472 -------- c:\windows\system32\dllcache\advapi32.dll
2009-04-15 16:43 453,120 -------- c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-15 16:42 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-04-15 16:42 215,552 -------- c:\windows\system32\dllcache\wordpad.exe

==================== Find3M ====================

2009-05-11 12:08 90,112 a------- c:\windows\DUMP7abd.tmp
2009-05-11 11:37 90,112 a------- c:\windows\DUMP7d8c.tmp
2009-05-11 11:28 50 a------- c:\program files\zioz.txt
2009-04-24 16:49 325,896 a------- c:\windows\system32\drivers\avgldx86.sys
2009-04-24 16:49 11,952 a------- c:\windows\system32\avgrsstx.dll
2009-04-24 16:49 50,968 ac------ c:\windows\system32\avgfwdx.dll
2009-04-24 16:49 29,208 a------- c:\windows\system32\drivers\avgfwdx.sys
2009-04-24 16:49 12,552 a------- c:\windows\system32\drivers\avgrkx86.sys
2009-04-24 16:49 108,552 a------- c:\windows\system32\drivers\avgtdix.sys
2009-03-21 09:06 989,696 -------- c:\windows\system32\dllcache\kernel32.dll
2009-03-19 16:32 23,400 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-06 09:22 284,160 a------- c:\windows\system32\pdh.dll
2009-03-05 23:59 1,900,544 a------- c:\windows\system32\usbaaplrc.dll
2009-03-02 19:18 826,368 a------- c:\windows\system32\wininet.dll
2009-03-02 19:18 826,368 a------- c:\windows\system32\dllcache\wininet.dll
2009-02-27 23:54 636,072 a------- c:\windows\system32\dllcache\iexplore.exe
2009-02-20 05:20 70,656 a------- c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:20 13,824 -------- c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 00:14 161,792 a------- c:\windows\system32\dllcache\ieakui.dll
2005-08-12 13:45 774,144 ac------ c:\program files\RngInterstitial.dll
2009-01-06 21:14 368 ac-sh--- c:\windows\system32\BKQAIkkj.ini2
2009-01-14 00:34 1,716,376 ac-sh--- c:\windows\system32\dNUuCJjl.ini2
2009-01-06 17:53 669,210 ac-sh--- c:\windows\system32\MTBKRqru.ini2
2009-01-12 00:02 675,920 ac-sh--- c:\windows\system32\nmWxbKkj.ini2
2009-01-06 17:53 702,378 ac-sh--- c:\windows\system32\OonTCJjl.ini2
2009-01-05 23:53 368 ac-sh--- c:\windows\system32\pYxGffii.ini2
2009-01-06 19:02 368 ac-sh--- c:\windows\system32\RYJjkUtv.ini2
2009-01-05 23:22 681,644 ac-sh--- c:\windows\system32\TtuuCJlm.ini2
2009-01-06 22:38 368 ac-sh--- c:\windows\system32\uxxaJRqr.ini2
2009-01-06 03:31 368 ac-sh--- c:\windows\system32\wEeeffhk.ini2
2009-01-06 01:13 368 ac-sh--- c:\windows\system32\XIOrYcdd.ini2
2008-09-25 03:09 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092520080926\index.dat

============= FINISH: 8:03:55.77 ===============

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Wed May 13, 2009 1:14 pm

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\program files\zioz.txt
    c:\windows\system32\BKQAIkkj.ini2
    c:\windows\system32\dNUuCJjl.ini2
    c:\windows\system32\MTBKRqru.ini2
    c:\windows\system32\nmWxbKkj.ini2
    c:\windows\system32\OonTCJjl.ini2
    c:\windows\system32\pYxGffii.ini2
    c:\windows\system32\RYJjkUtv.ini2
    c:\windows\system32\TtuuCJlm.ini2
    c:\windows\system32\uxxaJRqr.ini2
    c:\windows\system32\wEeeffhk.ini2
    c:\windows\system32\XIOrYcdd.ini2

    :reg
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders]
    "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Wed May 13, 2009 1:28 pm

OTMoveIt Log:
========== FILES ==========
c:\program files\zioz.txt moved successfully.
c:\windows\system32\BKQAIkkj.ini2 moved successfully.
c:\windows\system32\dNUuCJjl.ini2 moved successfully.
c:\windows\system32\MTBKRqru.ini2 moved successfully.
c:\windows\system32\nmWxbKkj.ini2 moved successfully.
c:\windows\system32\OonTCJjl.ini2 moved successfully.
c:\windows\system32\pYxGffii.ini2 moved successfully.
c:\windows\system32\RYJjkUtv.ini2 moved successfully.
c:\windows\system32\TtuuCJlm.ini2 moved successfully.
c:\windows\system32\uxxaJRqr.ini2 moved successfully.
c:\windows\system32\wEeeffhk.ini2 moved successfully.
c:\windows\system32\XIOrYcdd.ini2 moved successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SecurityProviders\\"SecurityProviders"|"msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" /E : value set successfully!
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\"Authentication Packages"|hex(7):6d,73,76,31,5f,30,00,00 /E : value set successfully!

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05132009_082656

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Wed May 13, 2009 1:29 pm

Okay, nearly done now.

  • Open HijackThis.
  • When Hijack This opens, click "Open the Misc Tools section"
  • Then select "Open Uninstall Manager"
  • Click on "Save List..." (generates uninstall_list.txt)
  • Click Save, copy and paste the results in your next post.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Phicol on Wed May 13, 2009 1:34 pm

2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
2007 Microsoft Office Suite Service Pack 1 (SP1)
3D Groove Playback Engine
Acronis True Image Home
Ad-Aware SE Personal
Adobe Flash Player 10 ActiveX
Adobe Reader 7.0.9
Adobe Shockwave Player 11
Agere Systems PCI Soft Modem
Apple Mobile Device Support
Apple Software Update
AVG 8.5
Bonjour
CDDRV_Installer
CIF USB Camera (2110A)
ExpressFX
Far Manager v1.70
Help and Support Additions
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB952287)
HP Boot Optimizer
HP Deskjet Printer Preload
HP Image Zone 4.8.6
HP Image Zone for Media Center PC
HP Photosmart Cameras 4.5
HP PSC & OfficeJet 4.7
HP Software Update
HP Tunes
In-Fisherman Freshwater Trophies
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
IntelliMover Data Transfer Demo
InterActual Player
InterVideo WinDVD Player
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 4
J2SE Runtime Environment 5.0 Update 6
Java(TM) 6 Update 13
Java(TM) 6 Update 7
Juniper Networks Secure Application Manager
KhalSetup
Logitech SetPoint
Malwarebytes' Anti-Malware
MetaFrame Presentation Server Web Client for Win32
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft ActiveSync 4.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007 Trial
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher 2007
Microsoft Office Publisher 2007 Trial
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Standard Edition 2003
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MobileMe Control Panel
Mozilla Firefox (3.0.10)
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
muvee autoProducer 4.0
muvee autoProducer unPlugged - HPD
Otto
PC-Doctor for Windows
Photo Story 3 for Windows
Photosmart 320,370,7400,8100,8400 Series
PLATO Web Learning Network Clients
PPTexpert PPTmovie
PS2
QuickTime
RealArcade
RealPlayer
Remove Microsoft Money 2005 installer
Remove Quicken New User Edition installer
Rhapsody Player Engine
Safari
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951550)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB951944)
Security Update for 2007 Microsoft Office System (KB960003)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft Office Excel 2007 (KB959997)
Security Update for Microsoft Office OneNote 2007 (KB950130)
Security Update for Microsoft Office PowerPoint 2007 (KB951338)
Security Update for Microsoft Office Publisher 2007 (KB950114)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB954326)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office system 2007 (KB956828)
Security Update for Microsoft Office Word 2007 (KB956358)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Visio 2007 (KB947590)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Sonic Encoders
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Spybot - Search & Destroy
Update for 2007 Microsoft Office System (KB967642)
Update for 2007 Microsoft Office System (KB967642)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 1 for Windows XP Media Center Edition 2005 with HDTV Support (KB873369)
Updates from HP
U-Storage Service
Viewpoint Media Player
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Format Runtime
Windows Media Player 10 Hotfix - KB894476
Windows Media Player 10 Hotfix [See KB889858 for more information]
Windows Vista Upgrade Advisor
Windows XP Media Center Edition 2005 KB888316
Windows XP Media Center Edition 2005 KB895678
Windows XP Service Pack 3

Phicol
Novice
Novice

Status :
Online
Offline

Posts : 11
Joined : 2009-05-11
OS : XP
Points : 27661
# Likes : 0

View user profile

Back to top Go down

Re: Win32/Cryptor Hijackthis Log included

Post by Belahzur on Wed May 13, 2009 1:45 pm

Hello.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

  • Adobe Reader 7.0.9
  • J2SE Runtime Environment 5.0
  • J2SE Runtime Environment 5.0 Update 10
  • J2SE Runtime Environment 5.0 Update 4
  • J2SE Runtime Environment 5.0 Update 6
  • Java(TM) 6 Update 7
  • Viewpoint Media Player

Then download and install [You must be registered and logged in to see this link.]

We can remove OTMoveIt now.

  • Please double-click OTMoveIt3.exe to run it again.
  • Press the green CleanUp! button.
  • Press Yes cleanup process prompt, do the same for the reboot prompt.
How is the machine running now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245039
# Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum