Announcement Banner
UNSOLVED

David Wrigley

updated

22 years ago

0

4489

May 21st, 2004 06:00

AVG and Proxy.5.Y

I have a new 8300, and I did have a virus problem (... don't know how, as the machine had just been repaired by a Dell engineer, and I had not setup my email accounts ....).
Anyway, I had run AVG and it flagged up the 'Proxy.5.Y' virus , and seemed to clean it.

I have run AVG and Trend Housecall and the PC comes up with a clean bill of health, but after several minutes of running AVG pops up with a Message saying it house found Proxy.5.Y in the following file, and suggests I run a full AVG Scan (which then finds nothing).

The file is:
C:\System Volume Information\_restore{huge long alpha-numeric}\RP36\A0000466.exe

This path seems to be hidden, even from a 'search system/hidden files' search.

Can anyone help?

TIA
  • ChrisRLG

    2 Intern

    •

    3945 Posts

    207

    0

    Posted May 21st, 2004 07:00

    It is hiding in system restore, Turn it off - reboot - and turn system restore back on.

    Instructions XP http://www.bay-wolf.com/dk.htm#4a

    Instructions ME http://www.bay-wolf.com/dk.htm#1

    Then post a hijackthis log for us to check,
    =================
    A post of a hijackthis log for the experts to advise.
    HijackThis From Here
    or one of these other links:-
    http://www.merijn.org/files/hijackthis.zip
    http://www.aluriasoftware.com/tools/hijackthis.zip
    http://mjc1.com/mirror/hjt/

    Important: Create a folder on the C: drive called C:\HJT.
    You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT. Unzip HijackThis into this folder. (See this link for graphical instructions)
    Then run, scan, save log, then in notepad copy the FULL log by copy and paste as a reply to this post and an expert with HijackThis Knowldge, will have a go at giving advice. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste
    Please note the list of experts names below, very few forum regulars here have had this training.

    DO NOT FIX ANYTHING WITH HIJACKTHIS WITHOUT EXPERT ADVICE
    , most of what it finds you need for normal MS Windows tasks.

    Known Spyware HijackThis fighters in DellTalk - If you are, and are not on the list please PM Me.

    TomCoyote (of http://tomcoyote.org/forums/index.php fame)
    YoKenny (Expert at TomCoyotes, Trusted Advisor Spywareinfo)
    baskar1234 (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
    ChrisRLG (Classroom Coordinator at TomCoyotes, Trusted Advisor Spywareinfo)
    Tuxedo Jack (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
    Yellowhammer (Trusted Advisor at Net-Integration, First Responder at Computer Cops)
    tashi (Teaching Assistant at TomCoyotes, Trusted Advisor Spywareinfo)
    therock247uk (In Training at TomCoyotes and Spywareinfo)
    irelynmisses (In Training at TomCoyotes and Spywareinfo)
    Texruss (Spyware Fighter at Wildersecurity, In Training at TomCoyotes)
    PGPhantom (Trusted Advisor at Spywareinfo)

    You could also go to one of the more specalist forums where more experts will be able to help.
    http://tomcoyote.com/forums/index.php
    http://forums.spywareinfo.com/index.php
    http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi (Home of Spybot S&D)
    http://boards.cexx.org/index.php
    http://www.wilderssecurity.com/index.php
    Do read the sites FAQ before posting, and advise your problem and what steps you have already done to try to cure your problem.

    I, and the other hijack experts mentioned above, are in all those sites (and more) with the same login names. You might get one of us at those sites also to anwser your log, but other experts will also be available.

  • 207

    0

    Posted May 21st, 2004 08:00

    Thanks Chris.

    I have done the restore off-on sequence as detailed.
    This is the Log I obtained from HiJackThis
    ----------------------------------------------------------
    Logfile of HijackThis v1.97.7
    Scan saved at 10:45:51, on 21/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Kerio\Personal Firewall\persfw.exe
    C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\WINDOWS\System32\GSICON.EXE
    C:\WINDOWS\System32\dslagent.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btbroadbandstart.com/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [F9C7C0A1] C:\WINDOWS\System32\ujbfsfrzlk.exe
    O4 - HKLM\..\Run: [Microsoft Update] wumgrd.exe
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\RunServices: [4063E8C4] C:\WINDOWS\System32\ujbfsfrzlk.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] wumgrd.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
  • ChrisRLG

    2 Intern

    •

    3945 Posts

    207

    0

    Posted May 21st, 2004 09:00

    Your virus http://uk.trendmicro-europe.com/enterprise/security_info/ve_detail.php?Vname=WORM_SDBOT.KY

    To remove :-

    Check these in hijackthis, AND WITH ALL OTHER WINDOWS CLOSED, fix checked.

    O4 - HKLM\..\Run: [Microsoft Update] wumgrd.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] wumgrd.exe

    The following have randomly named file names, and as such are normally malware, UNLESS you know what they are, and they are from a safe source, please check for removal.

    O4 - HKLM\..\Run: [F9C7C0A1] C:\WINDOWS\System32\ujbfsfrzlk.exe
    O4 - HKLM\..\RunServices: [4063E8C4] C:\WINDOWS\System32\ujbfsfrzlk.exe

    Then Reboot to safe mode (F8 on boot) and delete the following files/folders:-

    C:\windows\system32\wumgrd.exe
    And if checked above
    C:\WINDOWS\System32\ujbfsfrzlk.exe

    Then Reboot and post a fresh log for me to check.

  • ChrisRLG

    2 Intern

    •

    3945 Posts

    207

    0

    Posted May 21st, 2004 10:00

    This is my normal post for when you are clear - which you now are:-
    ------------------------
    How on earth did I get infected with all that spyware in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051
    Also available from here :- http://www.computercops.biz/postlite7736-.html or http://boards.cexx.org/viewtopic.php?t=957
    --------------
    Look at the info on my website regarding malware (Link below). Some things you can do to stop getting infected again:-

    Spybot S&D, Ad-aware Run weekly - or after a heavy internet session.
    Spybot S&D v1.3 also have a run time module that runs in the background.

    Spywareblaster & Spywareguard, first sets kill bits to stop known bad activeX controls installing, second acts like your AV to stop browser hijacks and installing of known badies.

    Also ie-spyad (Link on my site), puts 4000 bad sites in your restricted (banned) sites list, to stop you accidentaly getting sent to a bad site, it has optional list of "bad" adult sites to install as well.

    All those with links from my site. Do remember just like Anti-Virus they need to be updated regularly, I do mine weekly, Anti-Virus hourly.

    Another good program winpatrol from here.

    With these and a firewall in place I have to try various bad sites when checking peoples hijackthis logs looking to sort bad from good, and I have not yet been infected. Still time for it to happen LOL.
  • 207

    0

    Posted May 21st, 2004 10:00

    I appreciate your time on this Chris.

    I deleted WUMGRD.EXE, however in safe mode there was no sign of ujbfsfrzlk.exe.

    This is the current HiJack Log:

    Logfile of HijackThis v1.97.7
    Scan saved at 12:04:19, on 21/05/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Kerio\Personal Firewall\persfw.exe
    C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    C:\WINDOWS\System32\GSICON.EXE
    C:\WINDOWS\System32\dslagent.exe
    C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Winwall\Winwall.exe
    C:\HJT\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.btbroadbandstart.com/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
    O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
    O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
    O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - Startup: Winwall Autostart.lnk = C:\Program Files\Winwall\Winwall.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004033001/housecall.antivirus.com/housecall/xscan53.cab
  • 207

    0

    Posted May 21st, 2004 10:00

    Super !!!!

    many thanks
    DW