Unsolved

This post is more than 5 years old

3 Posts

229

December 31st, 2005 01:00

Win32:Trojan-gen : present or fixed ?

dear hi-jack swat team
I have read thru your "read this" type material
and believe I have followed your instructions.
 
I was recently infected with "scum" ware.
I received an AIM message , apparently
from a friend.
 In fact it was from a fiend!
The scumware went thru address books and
circulated its poison.
The IM contained a url.

When I clicked the url I was infected.
I was not aware that a url is potentially
as dangerous as an email attachment!
 
Big Ooops ! A Darwin awards candidate
has been spoted.
 
I was not really aware of the infection,
till other friends advised me of it.
 
I use XP pro with dial-up aol and ZoneAlarm,
AVG (grisoft), Ad-Aware,
and Spybot Search & Destroy.
I also let Symantec do an on-line scan
( excludes zipped files ).
All these failed to clean my system.
I obtained AVAST and I think this got rid
some of the malware
( Sign of "Win32:Trojan-gen. {Other}"  )
 
Well, I've now got up-to-date 
ZoneAlarm, AVG , Ad-Aware & Spybot.
Also now AVANT, cwshredder( Merijn etc )
Spy-sweeper (free scan only ) and xblocker_free.
I have turned off Sytem Restore
and ran all in Safe Mode.
 
For now the anti-scum-ware is finding nix,
but I'm not fully convinced.
 
So I've got the latest Hijackthis and run it.
The log mean could be in mandarin or sanskrit
for all it means to me !
 
I wonder if I might now call on your expertise
to advise on the hijackthis scan.
 
I have no experience of doing posts and threads
so, if I deviate from norms , kindly be lenient.
 
I await your deliberations with interest
( ie fear & hope ! )
 
Best Regards john aka jpos09
 
Here is the log from the scan
 
Logfile of HijackThis v1.99.1
Scan saved at 00:57:19, on 31/12/2005
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
F:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\HJT\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CapFax] C:\Program Files\Classic PhoneTools\CapFax.EXE
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [BTModemProtection] BTModemProtection.lnk
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [Zone Labs Client] F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [avast!] F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE
O4 - Global Startup: AOL 7.0 Tray Icon.lnk = C:\Program Files\AOL 7.0\aoltray.exe
O4 - Global Startup: Norton System Doctor.lnk = F:\Program Files\Norton Utilities\SYSDOC32.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - F:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - Unknown owner - F:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - F:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - F:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - F:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Indexing Service (cisvc) - Unknown owner - C:\WINDOWS\System32\cisvc.exe (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - F:\Program Files\Norton Utilities\NPROTECT.EXE
O23 - Service: Super Ad Blocker Service (SABSVC) - Unknown owner - F:\Program Files\SuperAdBlocker.com\Super Ad Blocker\SABSVC.EXE (file missing)
O23 - Service: Speed Disk service - Symantec Corporation - F:\PROGRA~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

 

3 Posts

January 16th, 2006 22:00

17jan2006:
 My system continues to mal-function.
 I believe I have a worm/trojan, but
 my various spyware and AV software
 is not cleaning it away.
Here is an instance:-
## formerly : ## jan2006:XP(pro):
   # start>all programs
   # >accessories>system tools
   # >system information
 --> displays potentially very
  useful system information
  via msinfo32.exe
## now ( evidence of infection )
 now the above simply invokes
 microsoft help&support screens
## This is also true if I use
# XP:start>run> msinfo32.exe
 

Message Edited by jpos09 on 01-16-2006 06:29 PM

3 Posts

January 31st, 2006 01:00

O well , all the experts on this site are entirely silent on this problem.

I guess i'll have to chuck my pc in a skip and buy a new one.

Not too sure that it's worth all the hassle , no real benefit, no pleasure

and the web seems a very nasty place full of poisonous malware .

Instead might just use it as a standalone typewriter.

 

No Events found!

Top