Welcome, Guest. Please login or register.
December 11, 2009, 01:04:48 PM

Login with username, password and session length

341711 Posts
37763 Topics
85744 Members

Latest Member: marymon76

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Looking for malware...created HijackThis log
« previous next »
Pages: [1] Go Down Print
Author Topic: Looking for malware...created HijackThis log  (Read 1295 times)
VGI
Comodo Loves me
****
Offline Offline

Posts: 103


« on: October 11, 2009, 09:05:11 PM »

Forgive me. I only have enough time to do a HijackThis system scan and save a logfile.
I know that I should make time to do all that I am asked to do in https://forums.comodo.com/virusmalware_removal_assistance/what_to_do_if_youre_infected_experience_rev3-t41380.0.html

Just the same, I'd like someone to take a look.

I am nowhere near knowledgable enough to truly understand the log below, but even I suspect the last entry to be EVIL. (last entry: O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe)

I also notice that HijackThis did not scan my other two hard disks. (I have three, one is partitioned)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:47:41 AM, on 10/12/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
d:\Program Files\Avast4\aswUpdSv.exe
d:\Program Files\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\PnkBstrA.exe
d:\Program Files\Avast4\ashMaiSv.exe
d:\Program Files\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Comodo\COMODO Internet Security\cfp.exe
D:\PROGRA~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
D:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [COMODO Internet Security] "D:\Program Files\Comodo\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] d:\PROGRA~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Logitech . Product Registration.lnk = C:\Program Files\Common Files\Logishrd\eReg\SetPoint\eReg.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = D:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: [at]xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs:   C:\WINDOWS\system32\guard32.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - D:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - d:\Program Files\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - d:\Program Files\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - d:\Program Files\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - d:\Program Files\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - D:\Program Files\Comodo\COMODO Internet Security\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe

--
End of file - 5350 bytes
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6533


Why not ? The choice is yours !


« Reply #1 on: October 12, 2009, 02:52:17 AM »

Hi,

PnkBstrA.exe is part of PunkBuster, which is on his own part again of games like Battlefield 2142 and America's Army. So it's a legit application.

In your hijackthis logfile, I haven't found anything, so you should be safe.

Hijackthis only checks the harddrive were Windows is installed on.

best regards,
eXPerience
Logged

VGI
Comodo Loves me
****
Offline Offline

Posts: 103


« Reply #2 on: October 12, 2009, 04:49:17 AM »

So far, I have made thorough scans using AVAST, Spybot S&D, and Malwarebytes.

Avast got these:
Win32:Spyware-gen [Spy]

F:\3Gb_backup\Psalm\downloads\Getright\getrt450.exe\%MAINDIR%\fsg.exe
Win32:Adware-gen [Adw]

D:\Gamez\Game_Patches\Arcanum\Arcanum1074_exe.ace\Arcanum.exe
Win32:Trojan-gen [Virus/Worm]




Also, I scanned using Spybot S&D. Disappointingly it did not find anything, which was surprising.


I was able to make a thorough scan using the latest updated Malwarebytes.
Malwarebytes got the most malware:

Malwarebytes' Anti-Malware 1.41
Database version: 2944
Windows 5.1.2600 Service Pack 3

10/12/2009 3:35:03 PM
mbam-log-2009-10-12 (15-35-00).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 469491
Time elapsed: 52 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 10

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
D:\Downloads & Drivers\Cracks\Sony Sound Forge\0fIKSt4146\Sony.Sound.Forge.v8.0.Incl.Keygen-SSG\keygen\keygen.exe (Trojan.Downloader) -> No action taken.
D:\Downloads & Drivers\Cracks\Sony Sound Forge\0k8wc359HZ\Keygen\KeyGen [ Sony Sound Forge 8.0d Build 128  ].exe (Trojan.Downloader) -> No action taken.
D:\Downloads & Drivers\Cracks\Sony Sound Forge\Zk3bMYvb81\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\keygen\keygen.exe (Trojan.Downloader) -> No action taken.
D:\Program Files\mIRC\mirc.exe (Trojan.Downloader) -> No action taken.
D:\Program Files\mIRC\backup\mirc.exe (Trojan.Downloader) -> No action taken.
E:\Downloads & Drivers\Cracks\Sony Sound Forge\0fIKSt4146\Sony.Sound.Forge.v8.0.Incl.Keygen-SSG\keygen\keygen.exe (Trojan.Downloader) -> No action taken.
E:\Downloads & Drivers\Cracks\Sony Sound Forge\0k8wc359HZ\Keygen\KeyGen [ Sony Sound Forge 8.0d Build 128  ].exe (Trojan.Downloader) -> No action taken.
E:\Downloads & Drivers\Cracks\Sony Sound Forge\Zk3bMYvb81\Sony.Sound.Forge.v8.0b.Incl.Keygen-SSG\keygen\keygen.exe (Trojan.Downloader) -> No action taken.
E:\Program Files\mIRC\mirc.exe (Trojan.Downloader) -> No action taken.
E:\Program Files\mIRC\backup\mirc.exe (Trojan.Downloader) -> No action taken.


I have since had Malwarebytes remove these infections.

Did I do good? I am sure that, I would be able to find more although I do believe I should use other anti-virus/malware programs.

Also, my LEXMA mouse still won't get detected.
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6533


Why not ? The choice is yours !


« Reply #3 on: October 12, 2009, 08:18:39 AM »

That spybot didn"t detect something doesn't surprise me, it's not what it used to be...

MBAM only found some cracks and Mirc, http://www.mirc.com/, not sure if you need it, if so, it was a false positive.

I don't know what files Avast got, I'm not much with the names Undecided.

I sujest you try A-squared antimalware free. (see guide) it has great detection, one of the best, but has a high FP's rate, so be carefull

best regards,
eXPerience
« Last Edit: October 22, 2009, 10:06:09 AM by eXPerience » Logged

VGI
Comodo Loves me
****
Offline Offline

Posts: 103


« Reply #4 on: October 14, 2009, 01:19:15 AM »

Will try A-Squared then.

About Spybot S&D, its immunization function is still great, right?
Logged
HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1480


« Reply #5 on: October 14, 2009, 02:23:13 AM »

About Spybot S&D, its immunization function is still great, right?

Not really.

All it's doing is adding hundreds of URL's to your HOSTS file, which can slow your system down.
Logged

VGI
Comodo Loves me
****
Offline Offline

Posts: 103


« Reply #6 on: October 18, 2009, 07:12:22 AM »

What does this adding of URL's do to make my system more secure?
Logged
Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 3189



WWW
« Reply #7 on: October 18, 2009, 07:16:45 AM »

EXP - Do you need to quote all of his post? It takes up most of the page needlessly..
Logged

E5200 2.5ghz [at] 3.33ghz, POV 9800gt 512mb, 2gb DDR2 RAM.  500gb. HDD


~~~
Trying to see if I can completely switch to linux Cheesy
jay2007tech
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 381


« Reply #8 on: October 18, 2009, 01:13:41 PM »

Quote
D:\Gamez\Game_Patches\Arcanum\Arcanum1074_exe.ace\Arcanum.exe
Win32:Trojan-gen [Virus/Worm]
in specific
Quote
Arcanum1074_exe.ace
The dual extensions caught my interest

Quote
Mirc
Do you use mirc??? Basicly do use IRC???

Quote
AVAST, Spybot S&D, and Malwarebytes.
IMO, Get rid of Spybot S&D.
If you feel you need another opinion, get "Prevx" to use for a second opinion.  You have to do the deletes manually.  If you feel it maybe a false positive, submit the file here and you get instant results on your screen (in a few minutes)
http://camas.comodo.com/cgi-bin/submit
Give it a few minutes, before the results show.  If you don't understand the results, copy and paste the results here and will give you an answer Smiley



Logged

It's hard being a crooked Admin when the files won't pass an md5checksum test.  But like any other good crooked Admin it can be done, it just takes time(and lots of it) and a few aspirins
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 6533


Why not ? The choice is yours !


« Reply #9 on: October 22, 2009, 10:07:47 AM »

EXP - Do you need to quote all of his post? It takes up most of the page needlessly..
Kyle, I deleted it.

Quote
D:\Gamez\Game_Patches\Arcanum\Arcanum1074_exe.ace\Arcanum.exe
Win32:Trojan-gen [Virus/Worm]
in specific
Quote
Arcanum1074_exe.ace
The dual extensions caught my interest
you have better eyes than me Wink. but I think you're wrong about this one =
http://spywarefiles.prevx.com/RRFCHF11237467/ARCANUM%20ENGLISH%20PATCH%201074.EXE.html

eXPerience
Logged

HeffeD
Comodo's Hero
*****
Offline Offline

Posts: 1480


« Reply #10 on: October 22, 2009, 07:41:06 PM »

What does this adding of URL's do to make my system more secure?

Your system will not make a connection to any URL listed in the HOSTS file. So the theory is that by adding all these URL's, you won't get any malware because your system can't visit those URL's.
Logged

Tags: malware  HijackThis 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.274 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com