Unsolved
This post is more than 5 years old
59 Posts
0
8205
September 5th, 2007 19:00
Possible Malware-related problems, need help with diagnosing and fixing
I'm running Windows XP Home Edition (SP1) on a DELL Inspiron laptop. I thought I had the computer well-protected from malware but recently, I began noticing suspicious symptoms coinciding with changing my anti-virus software from AVG to McAfee Enterprise provided by my company and upgrading Ad-Aware SE Personal to AdAware 2007.
The symptoms include numerous ads popping up while using Internet Explorer, frequently causing IE to hang and become unresponsive to the End Task command; many strange .exe processes showing in Task Manager, sometimes multiple processes with the same name; sometimes I run AdAware scans, delete the problems, run the scan again, and the same problems are identified again; general slowness and frequently the Desktop Explorer itself becomes unresponsive.
I tried following the steps outlined by DELL (Journal ID:
07248GSKWM, Article ID: 277075). In particular, I downloaded Spybot Search & Destroy and immunized. I also tried searching for Windows and IE updates, especially SP2. The updater found 63 updates! I downloaded these successfully, but during the installation phase, IE froze on 8 of 63 (Windows Messenger update) and I had to force a restart. After restarting, I tried again to update and a dialog box appeared saying I didn't have privileges to update and that I should contact my system administrator (ME!---albeit not a very good one apparently). Moreover, I can't even find or access my Control Panels anymore! (What happened?) As a last resort, I tried reinstalling Windows from the disk that came with the computer. Although this was successful, I still can't see the Control Panels in the Start menu and all of the aformentioned problems persist.
I'd be most appreciative if you could help me:
(i) diagnose and fix the problem and, just as important
(ii) help me with a strategy (software and software settings) that will provide me comprehensive protection (assuming I keep everything current going forward---virus defs., immunizations, Windows security patches, etc.)
Appended below is my Hijack this log. Thanks in advance for your help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:26:25 AM, on 9/3/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Scan saved at 9:26:25 AM, on 9/3/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\Documents and Settings\Annie Fowler\My Documents\?racle\userinit.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\McAfee\Common Framework\naPrdMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\avp.exe
C:\WINDOWS\mgrs.exe
C:\Documents and Settings\Annie Fowler\My Documents\?racle\userinit.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\vtr.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Win32 NT Adv Services] taskmngr.exe
O4 - HKLM\..\Run: [Camra Updates] serviceswu.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\RunServices: [Camra Updates] serviceswu.exe
O4 - HKLM\..\RunServices: [Win32 NT Adv Services] taskmngr.exe
O4 - HKCU\..\Run: [Camra Updates] serviceswu.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Sfl] "C:\Documents and Settings\Annie Fowler\My Documents\?racle\userinit.exe"
O4 - HKCU\..\Run: [autoload] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\Annie Fowler\svchost.exe
O4 - HKCU\..\Run: [Aida] "C:\PROGRA~1\CROSOF~1\ati2evxx.exe" -vt ndrv
O4 - HKCU\..\Run: [Brave-Sentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKCU\..\Run: [Apeo] "C:\WINDOWS\SCURIT~1\winlogon.exe" -vt ndrv
O4 - HKUS\S-1-5-18\..\Run: [USB Driver4] UpdateXP2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Camra Updates] serviceswu.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [USBDrives] msfirewalI.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Update XP64] xefamgzs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [LSASS32] ISASS32.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Microsoft Windows Update XP64] xefamgzs.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [USB Driver4] UpdateXP2.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [LSASS32] ISASS32.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Microsoft Windows Update XP64] xefamgzs.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantispyware.com/download/2007/download.php?file=2&aid=rrdef1_11_asr&lid=1034&affid=3
O17 - HKLM\System\CCS\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F50266D-7178-4E23-9E55-E4F2BBE8B86A}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\..\{B68AACF7-76E8-41B1-A977-7A28EAC38788}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O20 - AppInit_DLLs: c:\windows\system32\pmkjifc.dll
O20 - Winlogon Notify: 0 ¸ À - 0 ¸ À (file missing)
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: DPCDFR - C:\WINDOWS\SYSTEM32\DPCDFR.dll
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O21 - SSODL: CDVfQUB - {E4DC5B2C-4E76-F186-6D41-2218BC043068} - C:\WINDOWS\System32\nzmal.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: Windows Management Service - Unknown owner - C:\WINDOWS\System32\.exe (file missing)
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\printer.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dll
O2 - BHO: IEHlprObj Class - {ABCDECF0-4B15-11D1-ABED-709549C10000} - C:\WINDOWS\System32\vtr.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Win32 NT Adv Services] taskmngr.exe
O4 - HKLM\..\Run: [Camra Updates] serviceswu.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\System32\spoolsvv.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [avp] C:\WINDOWS\avp.exe
O4 - HKLM\..\Run: [smgr] mgrs.exe
O4 - HKLM\..\RunServices: [Camra Updates] serviceswu.exe
O4 - HKLM\..\RunServices: [Win32 NT Adv Services] taskmngr.exe
O4 - HKCU\..\Run: [Camra Updates] serviceswu.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Sfl] "C:\Documents and Settings\Annie Fowler\My Documents\?racle\userinit.exe"
O4 - HKCU\..\Run: [autoload] C:\WINDOWS\System32\drivers\svchost.exe
O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\Annie Fowler\svchost.exe
O4 - HKCU\..\Run: [Aida] "C:\PROGRA~1\CROSOF~1\ati2evxx.exe" -vt ndrv
O4 - HKCU\..\Run: [Brave-Sentry] C:\Program Files\BraveSentry\BraveSentry.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\System32\WinAvXX.exe
O4 - HKCU\..\Run: [Apeo] "C:\WINDOWS\SCURIT~1\winlogon.exe" -vt ndrv
O4 - HKUS\S-1-5-18\..\Run: [USB Driver4] UpdateXP2.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Camra Updates] serviceswu.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [USBDrives] msfirewalI.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Update XP64] xefamgzs.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [LSASS32] ISASS32.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Microsoft Windows Update XP64] xefamgzs.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [USB Driver4] UpdateXP2.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [LSASS32] ISASS32.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Microsoft Windows Update XP64] xefamgzs.exe (User 'Default user')
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O15 - Trusted Zone: http://*.turbotax.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://www.winantispyware.com/download/2007/download.php?file=2&aid=rrdef1_11_asr&lid=1034&affid=3
O17 - HKLM\System\CCS\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\..\{3F50266D-7178-4E23-9E55-E4F2BBE8B86A}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\..\{B68AACF7-76E8-41B1-A977-7A28EAC38788}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS1\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O17 - HKLM\System\CS2\Services\Tcpip\..\{29BE81B5-D22F-410B-9B8D-8F8AEF6CC5FA}: NameServer = 85.255.116.146,85.255.112.196
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.146 85.255.112.196
O20 - AppInit_DLLs: c:\windows\system32\pmkjifc.dll
O20 - Winlogon Notify: 0 ¸ À - 0 ¸ À (file missing)
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documents\Settings\bot.dll
O20 - Winlogon Notify: DPCDFR - C:\WINDOWS\SYSTEM32\DPCDFR.dll
O20 - Winlogon Notify: instcat - C:\WINDOWS\SYSTEM32\instcat.dll
O21 - SSODL: CDVfQUB - {E4DC5B2C-4E76-F186-6D41-2218BC043068} - C:\WINDOWS\System32\nzmal.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: Windows Management Service - Unknown owner - C:\WINDOWS\System32\.exe (file missing)
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 9050 bytes
End of file - 9050 bytes
No Events found!


alf82
59 Posts
0
September 24th, 2007 03:00
In addition, my Add/Remove Programs Control Panel is now populated with programs again.
I apologize for the previous misunderstanding regarding the CFScripts.
Before we get too far into the post-disinfection activities, I have a one quick question. I currently have 2 user profiles on my computer, one of which I've almost never used. So far I've been doing everything within the user profile that I use most of the time. Now, as a matter of housekeeping, I'd like to delete the other user profile since I never use it. Do I need to do any scans or generate any logs within this seldom-used profile before I delete it?
Appended below is a current HijackThis log for review.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:57:21 PM, on 9/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 6417 bytes
1972vet
3.3K Posts
0
September 24th, 2007 08:00
Look2Me-Destroyer.exe
VundoFix.exe
Combofix.exe
SmitfraudFix.exe
Rustock.b-fix.exe
gmer
You can keep the Killbox if you like but I would suggest you not use it for anything other than deleting temp files until you familiarize yourself with the application.
All other software we downloaded is free and yours to keep.
To answer some of your questions now:
Quote: If you think my machine is looking clean, would you be willing to help me with some steps to prevent or at least reduce the risk of this happening again and protect my identity and personal information when I communicate over the internet? (If we still have more disinfecting to do, perhaps you could ignore this post for now, and we could revisit it later.)
With my final reply, I will include some valuable information and reading material to give you a hand up.
I was thinking of following the instructions in "So how did I get infected in the first place?" (http://computercops.biz/postlite7736-.html).
A very good read and excellent advice to follow.
Do you recommend any additions, subtractions, or substitutions to these instructions?
None at all really...TonyKlein is one of us. He authored that web document quite some time ago. The advice has a well proven track record and if you follow the advice outlined there, you are indeed be less likely to become a victim of the malicious software that circulates the web. I would only add my opinion regarding the use of file sharing software. Regardless of the p2p software's apparent innocence, and the application itself may not be malicious or contain bundled malware, the files shared over the web are NEVER trustworthy. I think Tony points to that very well but I personally would make a stronger case for not using p2p software at all. Click here for information regarding the risks of using File Sharing software.
In addition, I have a couple of other questions related to this:
(1) I'd like to replace McAfee with AVG. Should I download the AVG installer first, then make the switch while disconnected from the internet? Do I need to make any changes to the AVG default settings?
blue>You should download the AVG installer first. Disconnect from the internet and Uninstall McAfee. Once the uninstall completes, reboot and Install the AVG antivirus application. Connect to the internet and download all the updates. Once the update completes, manually check for updates again. Repeat the checking for updates until the application no longer finds any.
(2) I know that upgrading to SP2 and installing all other patches and critical security updates to the operating system is essential, but I want to make sure the computer is sufficiently well-protected before using IE again to download the updates so that I don't become reinfected. What checklist of security measures should I take before downloading the updates to be sure that the computer will stay clean during the process?
Without pointing to this question, we have already answered while following through with the previously posted instructions.
(3) I'd like to clean out all of the programs and files on my computer that are unneeded, even if they don't pose a security risk. I will uninstall old, unneeded programs, but based on the information in the logs, do you see anything else (random files, drivers, utilities, etc.) that I could safely delete without consequence, if only to just free up HD space?
The only files we've remove so far have been malware and associated Registry keys. You can read This web document and find files that are safe to delete. As for programs...you can free up more space by removing programs you KNOW that you don't use or want. Before you do however, you should google search the program to make certain it is not something you need. When you run Disk Cleanup, you can click the "More Options" tab and peruse the Windows Components that you don't use. Removing them will also free up more disk space. Windows System Restore also uses a tremendous amount of resources and disk space to record snapshots of the operating system. This feature can use up gigs of hd space. You can reduce the amount of space that Windows reserves by clicking start-->control panel-->system...Find the System Restore tab and select your local hard drive (if you have more than one, you can turn off system restore to those drives. System Restore need only be running on the drive where Windows is located. Move the slider so that the amount of space used is at or near 500 mb's. That amount is more than sufficient for restore points.
(4) From now on, I will use Firefox for internet browsing that does not specifically require IE. I noticed that Apple is making Safari available for Windows. Have you had any experience with Safari, do you recommend it?
The only other second generation Browsers I would recommend are Mozilla Firefox and Opera.
(5) Based on the information in any of the logs, are you able to comment on the risks associated with any of these many infections? In particular, do any of these predispose or render me vulnerable to identity theft?
The absolute worst type of malware is exactly what you had. A rootkit infection creates an environement that allows a remote attacker to have administrative access to the root (Windows Administrator) of your system. I can think of nothing worse than for some unknown user sitting in a remote location of the world to have full access to your computer. Whoever that may be, person or bot, can review any information stored on your computer as well as what information they may have gleaned about key strokes or web sites visited. This indeed would have made you vulnerable to identity theft and you should take steps to notify your Bank and Credit Card company of the seriously compromised situation that your computer had endured. As well, you should change your user ID and Passwords for you computer log on information, and web sites that require user ID's and passwords.
With all that said, now let's run one more scan before we part. I'd still like to see a complete F-Secure scan:
Please perform this online scan: F-Secure Online Scanner Next Generation Beta
1. Click on the link " F-Secure Online Scanner Next Generation Beta".
2. You may receive an alert on the address bar at this point to install the ActiveX control.
3. Click on that alert and then Click Insall ActiveX component.
4. Read the license agreement and click " Accept".
5.Click " Custom Scan" and be sure the following are checked:
- Scan whole System
- Scan all files
- Scan whole system for rootkits
- Scan whole system for spyware
- Scan inside archives
- Use advanced heuristics
6. When the scan completes, click the " I want to decide item by item" button.7. For each item found, Select " Disinfect" and click " Next".
8. When done, click the " Show Report" button, then copy and paste the entire report into your next reply.
By the way...don't be alarmed at what F-Secure may find. Many of the items it flags will indeed be archived or quarantined items that we already removed.
alf82
59 Posts
0
September 24th, 2007 13:00
I will continue with this tomorrow or Wednesday evening.
In the meantime, I have a few quick questions.
(i) Referring to my previous question about the second, seldom-used User Profile, should I run the F-Secure scan in the second User Profile as well or will scanning in the one User Profile cover the entire computer? (If the latter, can I go ahead and just the delete the other User Profile?)
(ii) In addition to the programs you listed, can I go ahead and delete Fixwareout.exe as well?
(iii) I fully agree with your cautionary comment on P2P software. I can't recall ever using any of the common programs (Limewire, Kazaa, etc.). Do you see any remnants of any of these programs that suggest otherwise and that I need to delete? I use iTunes. Is this considered P2P? Does iTunes expose to security risks?
(iv) I'll assume I should run F-Secure before swapping McAfee for AVG. Let me know if you think I should swap AV programs first, then run F-Secure.
As always, thanks for your continuing help.
1972vet
3.3K Posts
0
September 24th, 2007 19:00
should I run the F-Secure scan in the second User Profile as well or will scanning in the one User Profile cover the entire computer? (If the latter, can I go ahead and just the delete the other User Profile?)
Since you asked the question, I should clear it up, as well for any other casual forum readers...if you scan using a user profile that has administrative rights, that scan is all encompassing and under normal circumstances, should be sufficient...there are those rare occasions that malware can complicate this issue...however, in your case, since your computer has been cleared of the most complicating malware issues, you can just delete the other user profile first, then scan with F-Secure.
(ii) In addition to the programs you listed, can I go ahead and delete Fixwareout.exe as well?
Yes indeed. Sorry I missed that one.
(iii) I fully agree with your cautionary comment on P2P software. I can't recall ever using any of the common programs (Limewire, Kazaa, etc.). Do you see any remnants of any of these programs that suggest otherwise and that I need to delete?
I don't recall if I did or not but if there are any, the only things you may need to delete are folders. You can check that by going to start-->all programs...see if you find any folders there pointing to programs that you no longer have. Delete those if present.
I use iTunes. Is this considered P2P? Does iTunes expose to security risks?
Itunes is fine...no worries there.
(iv) I'll assume I should run F-Secure before swapping McAfee for AVG. Let me know if you think I should swap AV programs first, then run F-Secure.
It's really as broad as it is long. There would only be a benefit during the scan due to the smaller footprint from AVG...this would speed up the scan a bit so it's your preference as it really makes no difference one way or the other as to the scans outcome. In either case, while you scan on line, it would also be less cumbersome to temporarily disable the real time scanning of any on board antivirus application.
Also, I don't recall off hand if you have a third party firewall included with McAfee or if you use a different one. I seem to think I would most likely have recommended ZoneAlarm or Kerio if you didn't. As you scan on line, it's not so crucial but before you go surfing, make sure you do have a third party firewall turned on as well as your a/v real time protection.
alf82
59 Posts
0
September 26th, 2007 11:00
I then ran the F-Secure scan. The log is appended below for review. Most of the items flagged were in the quarantine. Two identified as vundo.gen38 were found in C:\Windows. For two other files (I forget the names), "Disinfect" was not one of the options under "Actions", so I just set the action to "None". In addition, 82 files were skipped (why?). Do they need to be scanned through other means?
I uninstalled McAfee (and deleted the orphan folders left behind) and installed AVG. AVG also prompted me to update Roxio so I did that too. I downloaded all the updates for AVG. Let me know if you see evidence of any stray McAfee components that I still need to delete.
A new HijackThis log is appended below the F-Secure report text.
F-Secure report:
Scanning Report
Tuesday, September 25, 2007 21:29:10 - 02:18:22
Computer name: DD41RK31
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
--------------------------------------------------------------------------------
Result: 35 malware found
Packed.Win32.Tibs.bq (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\dlh9jkd1q5.exe.vir
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\dlh9jkd1q6.exe.vir
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\dlh9jkd1q7.exe.vir
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vedxg4am1et2.exe.vir
Password-protected-EXE (virus)
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip
Tracking Cookie (spyware)
System (Disinfected)
System
System
System
System
System
System
System
System
System
System
Trojan-Downloader.Win32.Agent.coq (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vedxga3me2.exe.vir (Renamed)
Trojan-Downloader.Win32.Agent.dlf (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vtr.dll.vir (Renamed)
Trojan-Downloader.Win32.Alphabet.gen (virus)
C:\qoobox\Quarantine\C\WINDOWS\avp.exe.vir (Renamed)
C:\qoobox\Quarantine\C\WINDOWS\mgrs.exe.vir (Renamed)
Trojan-Downloader.Win32.Alphabet.y (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\s2f5028.exe.vir (Renamed)
C:\qoobox\Quarantine\C\Program Files\s2f.exe.vir (Renamed)
Trojan-Downloader.Win32.ConHook.bg (virus)
C:\VundoFix Backups\pmkjifc.dll.bad (Renamed)
C:\qoobox\Quarantine\catchme2007-09-09_133915.61.zip\DPCDFR.dll
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\pmkjifc.dll.vir (Renamed)
Trojan-Downloader.Win32.Zlob.cju (virus)
C:\qoobox\Quarantine\C\Program Files\setup.exe.vir (Renamed)
Trojan-Proxy.Win32.Agent.ji (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vedxga4m1et4.exe.vir (Renamed)
Trojan-Proxy.Win32.Agent.om (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\spoolsvv.exe.vir (Renamed)
Trojan-Proxy.Win32.Xorpix.bk (virus)
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\vedxga4me1.exe.vir (Renamed)
C:\qoobox\Quarantine\C\Documents and Settings\All Users\Documents\Settings\bot.dll.vir (Renamed)
Trojan.Win32.Agent.aoy (virus)
C:\qoobox\Quarantine\C\DOCUME~1\ANNIEF~1\APPLIC~1\tmpAF.tmp.exe.vir (Renamed)
Trojan.Win32.KillAV.lz (virus)
C:\qoobox\Quarantine\catchme2007-09-21_ 10539.60.zip\SAM.SAV
Vundo.gen38 (virus)
C:\WINDOWS\ehiilm.ini
C:\WINDOWS\stuwvw.ini
C:\qoobox\Quarantine\C\WINDOWS\ssrqss.ini.vir
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 263628
System: 4880
Not scanned: 82
Actions:
Disinfected: 1
Renamed: 14
Deleted: 0
None: 20
Submitted: 0
Files not scanned:
??? ?%? IBERFIL.SYS
C:\PAGEFILE.SYS
C:\WINDOWS\TEMP\ZLT00ACF.TMP
C:\WINDOWS\TEMP\ZLT01FE9.TMP
C:\WINDOWS\SYSTEM32\BIOS1.ROM
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SAM
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.TMP.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
C:\WINDOWS\SYSTEM32\CATROOT2\EDB.LOG
C:\WINDOWS\SYSTEM32\CATROOT2\TMP.EDB
C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{D790D866-D4FC-4287-939F-4858AC49F12D}.BIN
C:\SYSTEM VOLUME INFORMATION\CATALOG.WCI\CIVP0000.001
C:\SYSTEM VOLUME INFORMATION\CATALOG.WCI\CIVP0000.002
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\INSTCAT.DLL.VIR
C:\Program Files\Zone Labs\ZoneAlarm\instmtdr.exe\FILE0020.DAT
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CISL0001.001
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CISL0001.002
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CIVP0000.001
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CIVP0000.002
C:\I386\BIOS1.ROM
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\ANNIE FOWLER\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\ANNIE FOWLER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip\related.htm
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AproposMedia.zip\libexpat.dll
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip\cfin
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer1.zip\cfout.txt
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer3.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer4.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ElitumEliteBar.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ElitumEliteBar1.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind1.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechYSB.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Applicati? ? U I ??? ?%? li>C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.TMP.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
C:\WINDOWS\SYSTEM32\CATROOT2? . O ?/? ?%? \WINDOWS\SYSTEM32\CATROOT2\TMP.EDB
C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{D790D866-D4FC-4287-939F-4858AC49F12D}.BIN
C:\SYSTEM VOLUME INFORMATION\CATALOG.WCI\CIVP0000.001
C:\SYSTEM VOLUME INFORMATION\CATALOG.WCI\CIVP0000.002
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\INSTCAT.DLL.VIR
C:\Program Files\Zone Labs\ZoneAlarm\instmtdr.exe\FILE0020.DAT
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CISL0001.001
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CISL0001.002
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CIVP0000.001
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CIVP0000.002
C:\I386\BIOS1.ROM
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\ANNIE FOWLER\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\ANNIE FOWLER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AlexaRelated.zip\related.htm
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\AproposMedia.zip\libexpat.dll
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearch.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer.zip\cfin
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer1.zip\cfout.txt
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer2.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer3.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer4.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ElitumEliteBar.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ElitumEliteBar1.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSideFind.zip\sbRecovery.reg
C:\Documents and Settings\All Users\Applicationg D
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-09-25
F-Secure AVP: 7.0.171, 2007-09-26
F-Secure Orion: 1.2.37, 2007-09-25
F-Secure Blacklight: 1.0.64
F-Secure Draco: 1.0.35, 0597-150-72
F-Secure Pegasus: 1.19.0, 2007-08-18
Scanning options:
Scan all files
Scan inside archives
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2006 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
alf82
59 Posts
0
September 26th, 2007 11:00
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:51:10 AM, on 9/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AAWTray] C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols3beta/fscax.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 6619 bytes
1972vet
3.3K Posts
0
September 26th, 2007 18:00
C:\VundoFix Backups\pmkjifc.dll.bad (Renamed)
...delete that and also, open your Spybot Search and Destroy, find the resover section and delete those entries. Since you also have deleted combofix, you can just delete the entire folder qoobox.
Navigate to and delete these files indicated in Bold:
C:\WINDOWS\ ehiilm.ini
C:\WINDOWS\ stuwvw.ini
Reboot.
Navigate to:
C:\Documents and Settings\All Users\Applicati? ? U I ??? ?%? li>C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.TMP.LOG
...and investigate your "Application Data" folder at that location. The PurityScan infection creates unreadable characters that show up in scan logs with a question mark...I doubt you find a folder that has a question mark in it's name but you may find two different folders. If so, inside one of those folders is the result of the infection that F-Secure found but didn't scan. The entire folder should be deleted but before we delete it, we need to compare it with the other folder with the same name at that same location.
Post back your findings. Thanks!
alf82
59 Posts
0
September 26th, 2007 19:00
I think I understood everything in your instructions through "Reboot".
I'm not sure I understand the last paragraph---and I should say that I'm not sitting in front of the infected computer right now, so maybe this will become more apparent when I actually navigate to the folder in question. But when you say "...inside one of those folders is the result of the infection that F-Secure found..." what is the "result" of the infection? Is it a file?
When I compare the folders, am I looking for something specific? That is, what findings can I post back that will enable you to identify which folder to keep and which to toss?
Again, perhaps this will be obvious when I actually try to do it.
Thanks!
1972vet
3.3K Posts
0
September 26th, 2007 20:00
when you say "...inside one of those folders is the result of the infection that F-Secure found..." what is the "result" of the infection? Is it a file?
When I compare the folders, am I looking for something specific? That is, what findings can I post back that will enable you to identify which folder to keep and which to toss?
Sorry, I should have been a bit more specific. When I say:
The PurityScan infection creates unreadable characters that show up in scan logs with a question mark...
I said that so you would understand why the question marks appear in the scan log.
I doubt you find a folder that has a question mark in it's name but you may find two different folders. If so, inside one of those folders is the result of the infection that F-Secure found but didn't scan.
The result of the PurityScan infection is the bogus folder. That folder is harmless by itself. It's just a residual that you can delete. I just want to be careful not to delete the wrong folder if indeed you DO find two of them...Note, I did say, "you may find two different folders". You may not. The F-Secure scan log may be showing something that is just peculiar to a particular security setting or application that appears somewhere within your Application Data folder.
Just take a look at the folder and post back any information you may find regarding two folders with the same name.
alf82
59 Posts
0
September 27th, 2007 03:00
I couldn't find either ehiilm.ini or stuwvw.ini in C:\Windows, even when I viewed hidden files and folders. I did a search of the entire HD for "ehiilm", "stuwvw", and "*.ini" and still wasn't able to find either ehiilm.ini or stuwvw.ini.
I navigated to C:\Documents and Settings\All Users\. I was only able to locate one (hidden) Application Data folder.
But I was able to find additional Application Data folders in C:\Windows\System32\Config\systemprofile and C:\Windows\System32\Config\systemprofile\Local Settings.
I also found a lone executable called updatesp in C:\. Do you know what this is? Can I delete it?
Thanks!
1972vet
3.3K Posts
0
September 27th, 2007 21:00
Those other application data folders are fine too.
alf82
59 Posts
0
September 27th, 2007 22:00
To what do you attribute the mysterious "disappearance" (I guess we'll know if they're really gone after the scan) of those two *.ini files from C:\Windows?
By the way, even though I deleted all the components of the utilities we used from the desktop and C:\, I noticed some files in C:\Windows with "gmer" and "catchme" in the name as I was hunting around for those *.ini files. Is this normal? Should I delete these as well? More generally, how can I be sure I found everything related to the utilities we used?
Thanks!
1972vet
3.3K Posts
0
September 27th, 2007 23:00
Last time you were still badly infected...this time the scan shouldn't take so long. When I scan there for example, it takes perhaps 45 minutes to complete...and that's scanning over 100,000 files.
To what do you attribute the mysterious "disappearance" (I guess we'll know if they're really gone after the scan) of those two *.ini files from C:\Windows?
I'm not sure if the last scan log was reporting that it found those in C:\Windows, or if it was reporting what it found in the combofix quarantine folder...it's just the way that particular log presented those files between the others that was a bit confusing. That's why I wanted you to delete everything harmless that F-Secure found and then scan again. I'd like to see if it shows up again in the next log.
By the way, even though I deleted all the components of the utilities we used from the desktop and C:\, I noticed some files in C:\Windows with "gmer" and "catchme" in the name as I was hunting around for those *.ini files. Is this normal? Yes
Should I delete these as well?
gmer and catchme are fine. If you never intend to ever user either of them again, you can delete them but leaving them there causes no harm or interference.
More generally, how can I be sure I found everything related to the utilities we used?
If you deleted them it should be sufficient.
alf82
59 Posts
0
September 30th, 2007 17:00
Note that I selected "Disinfect" for these 2 *.ini files even though the scan says "None". What do you recommend to remove those 2 *.ini files?
In addition, the scan took over 5 hrs. again (5:04 to be exact) to run through 263,000+ files. I have pictures and music files, but these number in the 100's. This leads me to suspect that my operating system is overly chunky. Could I have old copies of my system (old system restores) that could account for the large size that I could delete? Or can you think of any other reasons my file system could be so large?
Thanks.
The log from the F-Secure scan is appended along with a new HijackThis log if needed.
F-Secure log:
Scanning Report
Sunday, September 30, 2007 08:57:17 - 14:05:22
Computer name: DD41RK31
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\
--------------------------------------------------------------------------------
Result: 2 malware found
Vundo.gen38 (virus)
C:\WINDOWS\ehiilm.ini
C:\WINDOWS\stuwvw.ini
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 263796
System: 0
Not scanned: 29
Actions:
Disinfected: 0
Renamed: 0
Deleted: 0
None: 2
Submitted: 0
Files not scanned:
C:\HIBERFIL.SYS
C:\PAGEFILE.SYS
C:\WINDOWS\TEMP\ZLT05791.TMP
C:\WINDOWS\SYSTEM32\BIOS1.ROM
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SAM
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.TMP.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
C:\SYSTEM VOLUME INFORMATION\CATALOG.WCI\CIVP0000.001
C:\SYSTEM VOLUME INFORMATION\CATALOG.WCI\CIVP0000.002
C:\Program Files\Zone Labs\ZoneAlarm\instmtdr.exe\FILE0020.DAT
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CISL0001.001
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CISL0001.002
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CIVP0000.001
C:\PROGRAM FILES\DELL\SUPPORT\UI\SEARCH\CATALOG.WCI\CIVP0000.002
C:\I386\BIOS1.ROM
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\NETWORKSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
C:\DOCUMENTS AND SETTINGS\ANNIE FOWLER\NTUSER.DAT
C:\DOCUMENTS AND SETTINGS\ANNIE FOWLER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS\USRCLASS.DAT
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-09-26
F-Secure AVP: 7.0.171, 2007-09-29
F-Secure Orion: 1.2.37, 2007-09-28
F-Secure Blacklight: 1.0.64
F-Secure Pegasus: 1.19.0, 2007-08-25
Scanning options:
Scan all files
Scan inside archives
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2007 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:39:23 PM, on 9/30/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\ANNIEF~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\OnlineScanner.exe
C:\DOCUME~1\ANNIEF~1\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1188195863193
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188195832018
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - http://support.f-secure.com/ols3beta/fscax.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe (file missing)
--
End of file - 7217 bytes
1972vet
3.3K Posts
0
October 1st, 2007 03:00
Since I had you delete your VundoFix tool, you'll need to download it anew. It's just as well as there has been an update to that utility.
Download a fresh copy again Here.
- ehiilm.ini
Select Add Files -->Repeat until they are all loaded Then Close that Window.stuwvw.ini
mliihe.ini
wvwuts.ini
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears again at reboot (if it does).