Here's the chat log frm my MSN chat with XTo..
please read this and help him out.
Here's the HijackThis log:
please read this and help him out.
XTerminator - See You On The Other Side says:
look
XTerminator - See You On The Other Side says:
my comp is infected with this stupid trojan and i am in safe mode
XTerminator - See You On The Other Side says:
where my mouse etc is not working
XTerminator - See You On The Other Side says:
file name is wsock32.dll
XTerminator - See You On The Other Side says:
in the winnt/system32 folder
XTerminator - See You On The Other Side says:
trojan name is downloader.small.54.Z
XTerminator - See You On The Other Side says:
post this info on TE
XTerminator - See You On The Other Side says:
and u also try to find me info on this ASAP
XTerminator - See You On The Other Side says:
i cant use windows in safe mode for long
XTerminator - See You On The Other Side says:
tried stuff like
XTerminator - See You On The Other Side says:
replacing the file from the win2k cd
XTerminator - See You On The Other Side says:
no use...what happens when i try to start the comp
XTerminator - See You On The Other Side says:
it boots up till the time the window that states preparing network connections etc comes up
XTerminator - See You On The Other Side says:
after that it just reboots
XTerminator - See You On The Other Side says:
i can boot in safe mode
XTerminator - See You On The Other Side says:
but cant quarantine or repair the file
XTerminator - See You On The Other Side says:
i cant delete the file as it is under use
XTerminator - See You On The Other Side says:
both my hdds have been infected
XTerminator - See You On The Other Side says:
both have a seperate installation of windows
XTerminator - See You On The Other Side says:
replaced the same file on the other hdd with the one present in the win2k cd
XTerminator - See You On The Other Side says:
now it doesnt boot into safe mode as well
XTerminator - See You On The Other Side says:
AVG detects the trojan
XTerminator - See You On The Other Side says:
but each time it heals it or quarantines or tries to delete
XTerminator - See You On The Other Side says:
asks for reboot
XTerminator - See You On The Other Side says:
which i dont wanna do coz it will infect me further
XTerminator - See You On The Other Side says:
as it happened in the other installation
XTerminator - See You On The Other Side says:
thats just about the info....apart from this...my bro used the comp last more than 24 hrs ago to check mail and chat
XTerminator - See You On The Other Side says:
after that its been switched on around 11
Here's the HijackThis log:
Logfile of HijackThis v1.99.0
Scan saved at 23:08:56, on 12/15/2005
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINNT\asuskbservice.exe
C:\WINNT\System32\GEARSEC.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\tcpsvcs.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\MsiExec.exe
C:\WINNT\Explorer.EXE
C:\WINNT\anvshell.exe
C:\WINNT\SOUNDMAN.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\KM9801U\MMHotKey.EXE
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\PROGRA~1\KM9801U\HokHIDKC.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Anshul.HOME\Local Settings\Temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 172.16.1.3:3128
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *nofra*;<local>
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [KM9801U] C:\PROGRA~1\KM9801U\MMHotKey.EXE
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: Download using Download &Express - file://C:\WINNT\system32\MetaProducts\Add_Url.htm
O8 - Extra context menu item: Save Flash - res://C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll/210
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Flash - {43CF38F3-5AEC-45a3-AD31-04EB06E9C6CA} - C:\Program Files\UnH Solutions\Flash Saving Plugin\FlashSButton.dll (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF3B4D3A-EF82-44B6-9692-B5803185B4F7}: NameServer = 172.16.1.3,172.16.1.2
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASUSKeyboardService - ASUSTeK COMPUTER INC. - C:\WINNT\asuskbservice.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: %NVSVC.name% - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe