UNSOLVED

aryeh

updated

20 years ago

A

aryeh

2 Intern

147 Posts

0

1511

January 24th, 2007 16:00

Suspected virus

I stupidly downloaded a screensaver, then, not wanting it, uninstalled the programme. After I rebooted my computer, most of the programme shortcuts on Start had disappeared, also I could not connect to the Internet and had to fix my dial-up connection 
 
A scan with Microsoft Windows Defender shows:
1.CometSystems - Alert - High : Permit - Remove :  Status - Error encountered
 
MWD  reported " Error encountered - Code 0x80508017 - some actions couldn't be applied to potentially harmfull items. The items might be stored in a read-only location or folders that contain the items. Delete the files or folders that contain the items.   Category - Potentially Unwanted Software: Description - This Program  has potentially unwanted behaviour : Advice - remove this programme immediately.
I think this might refer to the Screensaver I downloaded.  Although I unistalled it, if this is the software MWD found, then I do not know how to find the files/folders that contain the items.
 
A scan with AVG & Spybot Search & Destroy did not show anything.
 
A scan with Panda Activescan showed two entries - this is the log:
 
Adware:adware/block-checker Not disinfected Location Windows Registry 
Spyware:Cookie/Statcounter    Not disinfected Location  C:\Documents and Settings\Brenda\Cookies\brenda@statcounter[2).txt
 
Under also HJT this log:
 
 Logfile of HijackThis v1.99.1
Scan saved at 17:53:20, on 24/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\System32\GEARSec.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\Program Files\Photodex\ProShowGold\ProshowGoldV.3\ScsiAccess.exe
C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Creative\MediaSource5\MtdAcqu.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: ESigil Browser Helper - {A968A4B4-C492-4834-B651-17602C3885C8} - C:\Program Files\Comodo\VEngine\ESigil.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Program Files\CoreStreet\SpoofStick\SpoofStickBHO.dll
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Program Files\CoreStreet\SpoofStick\SpoofStick.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Comodo Firewall] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MtdAcqu] "C:\Program Files\Creative\MediaSource5\MtdAcqu.exe" /s
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.5] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1B9935E4-8A50-4DD8-BD09-A7518723BF97} (Talisma NetAgent Customer ActiveX Control version 3) - http://etalk.epson.co.uk/netagent/objects/custappx3.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (CwlscInstall Object) - https://scan.safety.live.com/resource/download/scanner/en-us/wlscbase2213.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1125688522906
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {E56347B0-6C2B-4C2E-939F-EE513EAC80BC} (Creative Product Registration ActiveX Control Module) - http://www.creative.com/register/OCXs/CtORWebClientNoMFC.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7DDD54DA-2E0B-4B9B-8F0F-A05BE7937097}: NameServer = 62.24.252.135 62.24.252.134
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\Agent\PQV2iSvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\NPROTECT.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files\Photodex\ProShowGold\ProshowGoldV.3\ScsiAccess.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~1\SPEEDD~1\NOPDB.EXE
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
 
Please tell me:
1. How to find the files MWD refers to and if it is OK to delete them.
2. What to do with the items Panda activescan found
3. If there is anything to do after you have read the HJT log
 
I appreciate any assistance you can give me...aryeh
 
 
 
 
 
 
   
 
 
 
 
 
 
  • RKinner

    2 Intern

    5851 Posts

    290

    0

    Posted January 24th, 2007 17:00

    Nothing to panic about.  CometSystems is not very evil. More an annoyance.  See:
     
     
    As the above link says it adds these lines to the registry
     
    HKEY_LOCAL_MACHINE\SOFTWARE\Comet Systems HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "DM_Server"
     
    And this folder to your c drive.
     
    c:\Program Files\Comet Systems
     
    I'm pretty sure both Ad-Aware and Spybod s&d will get rid of all of this junk for you.
     
    Adaware
    and click on the Free Download button under AdAware SE Personal.
     
    Spybot S&D
     
    And look under Download for:
     
     
    Either should do the job.  Both are free.  Spybot tends to be a bit faster to run.
     
    Or you can do it manually.  You can Start, Search, For Files and Folders then under More Advanced Options, check the top three boxes then search for Comet Systems.  Delete any that you find.  If a folder won't delete then delete all the files in it first.  If a file won't delete, rightclick on it and uncheck the Read Only box and try again. 
     
    To get rid of the registry entries I prefer to use RegSeeker.
     
    Download regseeker.
    Click on where it says:
    DOWNLOAD RegSeeker 1.52 (>20 languages included !)  then when you get to the next page on Download. 
    IE may tell you that it doesn't want to download the file but click on the warning line and download it.

    Save it to your desktop then rightclick on it and Extract it to C:\reg (new folder) or Open it With WinZip. 

    Then run regseeker.exe (Start, Run, C:\reg\regseeker.exe, OK.  It should start the program.  Select Find in Registry then check all of the HKEY entries and search for "comet systems".
    Then Select All, Select All, rightclick on the selection and Delete Selected Items.
     
    Repeat for dm_server.
     
    Your log only shows one remnant from Norton:
     
    O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)

     
    Close IE.  Run HJT, scan only, check the box in front of the above then Fix Checked.
     
     
     
    Ron
     
     
  • aryeh

    2 Intern

    147 Posts

    290

    0

    Posted January 26th, 2007 09:00

    Thank you for your reply. Could cometsystems have altered the behaviour on my computer (as described in my 1st post) as I am concerned something else might still be lurking.
     
    I already had AdAware & Spybot, scans did not show cometsystems. Search also did not show anything.
     
    I downloaded RegSeeker and a scan only showed cometsystems but not dm_server. I am concerned about doing anything to the Registry as I do not have the knowledge to backup it up
    or restore if necessary. Is it OK just to delete the entry RegSeeker found?
     
    Lastly, what should I do about the two entries found with Panda activescan.
     
    Hope you will advise me further...aryeh
     
     
     
  • RKinner

    2 Intern

    5851 Posts

    290

    0

    Posted January 26th, 2007 11:00

    You can let regseeker delete the cometsystems entry.  It's pretty good and never seems to mess up when it does that sort of thing.
     
    CometSystems was probably not the reason your shortcuts disappeared.  It's not supposed to do much of anything more than give you some ads.  It sort of sounds like you got logged on to a different profile.  Let's run some other checks and see if we see anything.
     
    Check for a bad file in System32:
    Start, Run, sigverif, OK then press Start and wait for the program to finish.  When it finishes sort the output by date by clicking on the Modified column header once or twice.  Look for files with .exe, .dll or .sys extensions that were modified about the time the problem started.
     
    Blacklight Rootkit Detector:
    Download Blacklight trial from here: http://www.f-secure.com/blacklight/
    Hit "I accept." It will take you to the download page. Download blbeta.exe and save it to the Desktop. Once saved... double click blbeta.exe (you may not be able to see the .exe) to install the program. Click Accept Agreement and click Scan This app may trigger a warning from your antivirus. Let the driver load. Wait for it to finish. If it displays any items...don't do anything with them yet. Just hit exit (close) It will drop a log on Desktop that starts with fsbl....big number
    Please post contents of log in your next reply.  More instructions with pictures here:
     
    Check the Event logs for errors:
    Start, Run, eventvwr.msc, OK then select System.  Look for red marked files that have a time stamp about the time of the problem.  Open the event then click on the bottom of the three buttons to copy the text.  Move to a reply and Edit, Paste.  Repeat for any other different errors that happened around the time of the problem or since the last reboot.  Please don't go back to the beginning of time and no events from a Safe Mode boot.  Repeat for Application.  If your PC speaks something other than English don't translate it unless it doesn't use the Latin alphabet and then please include the timestamps.
     
     
    Let's make sure it's not a harddrive problem:
     
    A Disk Check:
    Run a disk error check and see if your harddrive has problems.  Start, My Computer then right click on Local Drive C and select Properties (verify that it shows you have at least 15% free) then Tools, Error-Checking => Check Now.  Check the 2 boxes then Start.  It will tell you it can't do it now but will be glad to schedule it for your next boot.  Tell it OK. When you reboot it will check your drive which usually takes 30-60 minutes.  Sometimes it will even fix your problems while it is at it.
     
    Ron
     
     
  • aryeh

    2 Intern

    147 Posts

    290

    0

    Posted January 26th, 2007 16:00

    Bad file in System 32
    Nothing shown
     
    Blacklight Rootkit Detector
    Nothing detected with the scan
     
    Event logs
    System: Red check  marks by Service Control/DCOM/WinDefend - no buttons in the Event Properties box that opened when I clicked on the event.
     
    Application
    Many entries with red check marks on different types of entries (more than above) but again no buttons
     
    Am I missing something in the Event log?
     
    Disk Check
    At least half of the disc space is free
    Disk error check - no errors
     
     Many thanks...Aryeh
     
     
     
     
     
     
     
  • aryeh

    2 Intern

    147 Posts

    290

    0

    Posted January 30th, 2007 07:00

    Please could you reply to my last post re the Event Log
     
    "Event logs
    System: Red check  marks by Service Control/DCOM/WinDefend - no buttons in the Event Properties box that opened when I clicked on the event.
    Am I missing something in the Event log?"
     
    and what should I do re the the items found with the Panda activescan?
     
    Also is there anything else I should do to resolve my problem?
     
    Thank you...aryeh
     
     
     
  • RKinner

    2 Intern

    5851 Posts

    290

    0

    Posted January 30th, 2007 08:00

    Sorry, I missed your reply somehow.  In the Event Log you needed to doubleclick on the error to see the buttons but the Windows Defender Error probably means you are running the Beta version which expired 1/1/7 so uninstall Windows Defender and get the new version.
     
     
    The Application errors would be interesting to see.
     
    Regseeker should have removed the cometsystems stuff and the tracking cookie is nothing to worry about so Panda Scan has probably been  been taken care of.  You can run it again to be sure.  Just ignore any tracking cookies it finds.
     
    Try Kaspersky's online scan.  I think it's a bit better than panda.
     
     
    What symptoms do you still have other than some shortcuts missing from the desktop?
     
    Ron
     
     
     
     
  • aryeh

    2 Intern

    147 Posts

    290

    0

    Posted February 1st, 2007 13:00

    Scan with Kaspersky was clean
     
    Symptons before  suspected download:
    Very many shortcuts disappeared from Start
    A few shortcuts disappeared from the desktop
    Dial connection to the Internet would not work
    My screensaver was no longer appearing on the screen
    Thumbnail image by my name (after turning on the computer from Standby) had changed to a  different image
     
    The only problem I seem to be having now is that sometimes my mouse pointer disappears, usually when I am on the Internet.
     
    Event Log
    System Errors:  many red check marks (before and after the time of the suspected download) for Service Control/DCOM/WindDefend. There were no buttons showing after I clicked on the errors
    Application: many red check marks (before & after the suspected download) for Automatic Liveupdate/Userenv.Again, there were no buttons showing after I clicked on the errors.
     
    Unfortunately, the Event log does not now go back to the date time stamp for all of the dates of the suspected download.
     
    Re RegSeeker: You said that this "doesn't mess up". Does this also apply to Cleaning the Registry? A scan showed many errors - is it OK for me to use this function (bearing in mind that I do not know how to do a backup or to restore the Registry)
     
    I look forward to your reply.
    Thank you/aryeh
     
     
  • RKinner

    2 Intern

    5851 Posts

    290

    0

    Posted February 1st, 2007 14:00

    Symptoms:
    What appears to have happened is that you had a problem caused by the install/removal of the screensaver and it went back in time to an earlier state.  It does not appear that you have any infection.
     
    Events:
    Uninstall Windows Defender and download the latest version and reinstall.  I think it has expired.
     
    Not sure what LiveUpdates' problem is.  It's the little program that goes to symantec to get new updates.  Perhaps your subscription has expired?  Have you tried to do an update to Symantec using it?  Is the Symantec a paid up subscription or a trial?   You might want to get the free one from Avast that works about as well and takes up a lot less of your PC's resources.  http://www.avast.com/eng/download-avast-home.html
     
    You really should be able to open the events.  Try rightclicking on them and select Properties.
     
    RegSeeker.   The program does a good job of finding and safely removing things we search for but I don't know how well it does the registry cleaning.   I am not a big fan of regcleaning in general.  Most of the errors they find are trivial and unless you have a backup of the registry (preferably with a copy of the XP CD) and know how to use it I'd rather not try it.
     
    Ron
     
     
     
     
  • RKinner

    2 Intern

    5851 Posts

    370

    0

    Posted February 1st, 2007 15:00

    Your last log showed a ton of Symantec stuff.  Is that from Norton System Works or something like that?  Symantec is known for being a poor uninstaller.  They even make a program to go back in and uninstall the stuff they missed.   
     
     
    It's not perfect either. 
     
    Post a new hjt log when done and let's see if it missed anything.
     
    You could try a different mouse and see if it helps. 
     
    I will have to research the problem with the buttons missing from the events.  The Events do open for you just without buttons.  Do they give the text of the message or is that gone too?
     
    Ron
  • aryeh

    2 Intern

    147 Posts

    290

    0

    Posted February 1st, 2007 15:00

    Thank you for your speedy reply.
     
    Re Windows Defender - I already have the latest version.
     
    I no longer use Norton, instead AVG (free)
     
    Re Events log, I had already tried selecting Properties and still no buttons on the errors I mentioned in my last post. There are buttons on events that are not applicable to my problem.
     
    Have you any thoughts on the other errors I mentioned in my last post?
     
    Do you think the problem with my mouse has anything to do with my problem?
     
    I will take your advise re RegSeeker.
     
    Is there anything else I should do> 


    Message Edited by aryeh on 02-01-2007 11:27 AM