To talk on Icrontic, just register!

It only takes 30 seconds.

Have an account? Sign in:

Forgot?

To reopen your thread, send a Private Message (PM) to Trogan with a link to your thread.

If you are not the user who started this thread, you must start your own thread instead.

 
Reply to Discussion Options
fingerflinger
Mid-Western Mountaineer
fingerflinger
36 Posts

Veritable Mountain of Viruses

Hey guys, I'm here with one of my friends, trying to clean up his computer, but I've reached my limit of expertise, and bow to all of your greater knowledge.

Basically, I can't seem to shake the New.Net stuff, and some other background processes that I can't even track down. I'll post the HJT log, and if anybody can find the time to help me out, I'd appreciate it. Gracias.

Logfile of HijackThis v1.99.1
Scan saved at 8:55:07 PM, on 7/13/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\U2thZ2dz\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark 2300 Series\lxcgmon.exe
C:\Program Files\outlook\outlook.exe
C:\WINDOWS\System32\ssn6tuu.exe
C:\WINDOWS\System32\nr1rnqm8.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Common Files\{E03209E6-0256-1033-0414-010323200001}\Update.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\svchost.exe
C:\WINDOWS\System32\lxcgcoms.exe
C:\Documents and Settings\Skaggs family\Desktop\HijackThis.exe
C:\WINDOWS\system32\rundll32.exe

F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\uluap.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,ghceacy.exe
O2 - BHO: Yvakt Class - {AE0ECC2F-0C33-494C-8B22-B57A7763027F} - C:\WINDOWS\System32\x3cqp0.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O4 - HKLM\..\Run: [lxcgmon.exe] "C:\Program Files\Lexmark 2300 Series\lxcgmon.exe"
O4 - HKLM\..\Run: [outlook] C:\Program Files\outlook\outlook.exe /auto
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [Hhl7RfpJ] "C:\WINDOWS\System32\ssn6tuu.exe"
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,ClientStartup -s
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - Global Startup: svchost.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4FAE30E1-EE9C-477D-8D06-BF8D3429B60F} (WebIQ Technology Client) - http://webiq001.webiqonline.com/WebIQ/bin/WebIQ.cab
O16 - DPF: {55F2FE00-C6E1-11D4-84BC-009027889212} (Seagate DiscWizard English) - http://www.seagate.com/support/disc/...n/npdscwiz.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O18 - Filter: text/html - {DA28E0DB-229C-4003-827E-96AE15AD90FB} - C:\WINDOWS\System32\x3cqp0.dll
O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\system32\en2ql1f51.dll
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\U2thZ2dz\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: lxcg_device - Unknown owner - C:\WINDOWS\System32\lxcgcoms.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\System32\wdfmgr.exe (file missing)
__________________ Pentium 4 2.8C
ASUS P4P800
ATI 9800 Pro
1 Gig of DDR PC3200
Western Digital 160 Gig 7200 RPM
Lite-On 8x DVD Burner
400W PSU
jmoney3457
In malware training:]
jmoney3457
1,396 Posts
hi flinger.. lets get rid of the new.net you mentioned first please do the following: Please download LSP-Fix from the following link and save it to a location you can find later if necessary.

LSP-Fix Download Link

To remove New.net. please go to Add/Remove Programs via Control Panel, look for and remove New.Net. If you can't find it, then please go here and follow the removal instructions in Procedure 4 at the bottom of the page.


If you can not connect to the Internet after removing New.net, please run the LSP-Fix program I had you download earlier, and click on the finish button. Reboot and you should be able to get back on. & then please post new HJT log along w/ how the new.net removal went
__________________

[folding_sig1]
fingerflinger
Mid-Western Mountaineer
fingerflinger
36 Posts
Thanks for responding money, but we finally just decided to reinstall XP. As far as New.Net, I actually was able to remove the O10 instances, but there was another instance that initialized at startup. This one reinstalled the other New.Net stuff, and I couldn't remove it. Do you know anything about this?
jmoney3457
In malware training:]
jmoney3457
1,396 Posts
did u just reinstall xp after my post?
fingerflinger
Mid-Western Mountaineer
fingerflinger
36 Posts
No, we did it later that night.
jmoney3457
In malware training:]
jmoney3457
1,396 Posts
No, we did it later that night.
oh, could you please post a fresh HJT log just to be sure..
fingerflinger
Mid-Western Mountaineer
fingerflinger
36 Posts
Yeah, I'll get one up next time I'm at his house.
Similar Threads
Thread Thread Starter Forum Replies Last Post
Many problems with computer - viruses? DryIce198 Resolved / Inactive 5 24 Jan 2006 10:18am
Infected with several viruses, HijackThis Log Included - Please Help! (CA_Dude) CA_DUDE Resolved / Inactive 11 7 May 2005 2:33pm
HijackThis! Log & Help Removing Viruses AVG Can't Heal - kennyg123 kennyg123 Resolved / Inactive 2 11 Feb 2005 3:31pm
getting rid of my computer viruses Ferg Resolved / Inactive 1 17 Sep 2004 9:56am
Macs invulnerable to viruses! Camman General Banter 13 11 Sep 2003 9:02am

Go Back   Icrontic Forums > Malware Help > Spyware & Virus Removal > Resolved / Inactive
Jump to
This Thread Search this Thread
Search this Thread:

Advanced Search


Current time: 9:25pm (GMT)
Powered by vBulletin®
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Get Vanilla instead. Trust me.