Help - Search - Members - Calendar
Full Version: Can't access my task manager ...
Gladiator Security Forum > Malware Help Forum > HELP! Think you are Infected?
EvangelionAngel2
I can't seem to access my task manager, and I've also found three folders that something keeps downloading files into automatically.

Here's the folders that things keep ending up downloading into.
QUOTE
c:\Documents and Settings\Owner\complete
c:\Documents and Settings\Owner\My Documents\my music\_
c:\Documents and Settings\Owner\My Documents\_


Here's my Hijackthis logfile.

QUOTE
Logfile of HijackThis v1.99.1
Scan saved at 12:41:38 AM, on 6/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\WINDOWS\qjdrsxf.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe
C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WUSB54GC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\AOL\1175219056\ee\AOLSoftware.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\qjdrsxfA.exe
C:\WINDOWS\cfg32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\cfg32a.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Documents and Settings\Owner\My Documents\Programs\Programs\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {A27F1958-7EC0-4858-A24E-2FE99AC0984B} - C:\Program Files\Common Files\quso.dll
O2 - BHO: 0 - {D34F5400-0D2D-47C1-419D-F192F4DCA391} - C:\Program Files\MSN Gaming Zone\tefati.dll (file missing)
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1175219056\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [qjdrsxfA] C:\WINDOWS\qjdrsxfA.exe
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA9386] command /c del "C:\WINDOWS\cfg32r.dll_tobedeleted_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC7898] cmd /c del "C:\WINDOWS\cfg32r.dll_tobedeleted_old"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\RunOnce: [SpybotDeletingB9002] command /c del "C:\WINDOWS\cfg32r.dll_tobedeleted_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8030] cmd /c del "C:\WINDOWS\cfg32r.dll_tobedeleted_old"
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: svchost.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Net Agent - Unknown owner - C:\WINDOWS\dls0523pmw.exe
O23 - Service: WUSB54GCSVC - Unknown owner - C:\Program Files\Compact Wireless-G USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GC.exe (file missing)
Bobbi Flekman
Hi EvangelionAngel2,

You are infected with a backdoor Trojan. As you noticed, that keeps downloading stuff and even worse... Uploads stuff. This can mean creditcard information, bank account information, passwords. In other words, all sorts of stuff you don't want others to have! Your best course of action is to reformat the system, as we won't be able to find all and exactly what is there.

I'm sorry, if I can assist with the reformat, please let me know.
EvangelionAngel2
If I reformatted my system, what exactly would I lose? And how would I go about reformatting?
Bobbi Flekman
Hi EvangelionAngel2,

QUOTE
If I reformatted my system, what exactly would I lose? And how would I go about reformatting?
You would lose everything that is on the computer. So before taking the step it would be best to make a backup of the current harddisc. That way you won't lose any documents, music, pictures, etc. And as long as you only transfer data from your backups back to the hard disc you won't have to be afriad of reinfecting the system.

How to go about reformatting.... That depends on the computer. Most laptops come with a Restore CD or partition that will set the system back to the state it was when you bought the computer. Other computers get distributed with a copy of the Operating System. Personally I have both of them, a laptop with a Restore CD and a computer with the discs of Windows 2000. So the real question is what computer do you have? Do you know if you have a Restore Partition/CD? Or do you have the discs to Windows XP?

Can you burn CDs/DVDs with your computer (for the backup of the hard disc)?
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.