Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.| Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post. - BleepingComputer Management |
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
![]() ![]() |
Aug 5 2008, 06:04 PM
Post
#31
|
|
|
Multi Megaton Malware Munition ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 4,882 Joined: 17-January 08 From: Northfield, Ohio Member No.: 184,215 |
Yes, I have an idea of what might be going on there Try this: We need to repair some of windows' internal registration settings
Billy3 -------------------- The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
|
|
|
|
Aug 6 2008, 12:04 AM
Post
#32
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 28-June 08 Member No.: 219,148 |
Hi Billy,
Okay I ran Dial-A-Fix, seemed to run, but still cannot d/l either XP SP3 or the eset.com online scanner. I did reboot a few times, ran Dial-A-Fix a few times...all to no avail. Any other ideas? |
|
|
|
Aug 6 2008, 12:31 AM
Post
#33
|
|
|
Multi Megaton Malware Munition ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 4,882 Joined: 17-January 08 From: Northfield, Ohio Member No.: 184,215 |
Hello, capt.frito.
You can obtain a stand alone copy of SP3 from here: http://www.microsoft.com/downloads/details...;displaylang=en Let's try a different onlinescan. Your system may have been set to block ActiveX Controls which would disable both Windows Update and ESET. What version of Internet Exploder are you using? Please do an online scan with Kaspersky WebScanner.
In your next reply, please include the following:
Billy3 -------------------- The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
|
|
|
|
Aug 6 2008, 01:05 AM
Post
#34
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 28-June 08 Member No.: 219,148 |
Hi Billy
This machine has IE7 7.0.5730.11 on it. I used the Windows Update successfully since we've been working together. At some point over the past week it just quit working. I spent some time trying to allow eset.com into a trusted zone with very few restrictions on the site (much more liberal than any other settings I've ever made before). Same with Windows Update. I'll try the manual patch and see if that gets us back to something better. I did run Kaspersky's earlier too (you can look back through the posts if to see when and where...) best, Frito |
|
|
|
Aug 6 2008, 10:23 AM
Post
#35
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 28-June 08 Member No.: 219,148 |
Hi Billy,
Good news, SP3 seems to have fixed the Windows Update problem. I applied the patch manually, then went to the update site and it found an additional high priority patch, downloaded it and applied it just fine. I will reboot and try eset's scanner one more time, and if it works I'll post the log. If not I'll use Kaspersky's and post that instead. best, Frito |
|
|
|
Aug 6 2008, 10:46 PM
Post
#36
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 28-June 08 Member No.: 219,148 |
Hi Billy,
Latest update... I have upgraded IE7 to the latest release. It now operates with Windows Update just fine. I now have all the latest patches applied, including SP3 and a few post-SP3 security patches and IE7 security patches. I tried again to run eset.com's online virus scanner. The trouble is that the box we're rescuing cannot verify the publisher and so Windows refuses to run the ActiveX control. I placed eset.com in the "trusted zone", then set the security to "low" which I believe should allow the control to run, but it still says blocked by Windows because the publisher is unknown. I tried forcing all IE7's settings to "factory default", but still no joy. Just to make sure it's not a local networking issue, I ran eset's online scanner from my own Windows box. While it gave me some cautions about the ActiveX control, it still recognized the publisher correctly, let me run it, and scanned my machine. (Recall that the machine we're working on belongs to a friend). Also note that my IE7 install is all default settings -- I only use IE for Windows Updates, period. Otherwise it's Firefox (on Windows) plus any number of others on Linux. Anyway, I did not have to anything fancy like making eset.com a trusted site. It just worked. So odds are that it's a problem with the infected machine. I have just started Kaspersky's, which will have to do until we get the unsigned control issue ironed out. I'll post the log when it completes (i.e., shortly). Any ideas on the unsigned control problem? best, Frito |
|
|
|
Aug 6 2008, 11:55 PM
Post
#37
|
|
|
Multi Megaton Malware Munition ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 4,882 Joined: 17-January 08 From: Northfield, Ohio Member No.: 184,215 |
It may be that ESET is down... sometimes things happen
That's why we have backup tools Billy3 -------------------- The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
|
|
|
|
Aug 7 2008, 10:18 AM
Post
#38
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 28-June 08 Member No.: 219,148 |
Hi Billy
Kaspersky just completed. A further thought on eset.com's scanner -- I don't think that it's a "site down" issue. I ran the scanner on a different machine (on the same network, with the same firewall rules applied to both machines, both XP SP3, same IE7 version) and it ran fine and reported the ActiveX control's publisher correctly. I have tried this over a period of several days. I have d/l'ed the 30 trial version of their NOD32 AV product. I will install it (first removing AVG) if you think it's a good idea. This PC's owner will have to decide on an AV product anyway, and eset's seems s good as any. Here's the log:
best, Frito |
|
|
|
Aug 7 2008, 08:33 PM
Post
#39
|
|
|
Multi Megaton Malware Munition ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 4,882 Joined: 17-January 08 From: Northfield, Ohio Member No.: 184,215 |
Hello, capt.frito.
I'm not sure why ESET won't run on your system... online scanners can sometimes be very finicky. I want to get rid of those files KAV found and run one more check.. (I'm not so keep on it's detection rate...) If this comes back clean you should be okay We need to move some files Please download the OTMoveIt2 by OldTimer.
We need to run a scan using the F-Secure Online Scanner
In your next reply, please include the following:
Billy3 -------------------- The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
|
|
|
|
Aug 7 2008, 11:13 PM
Post
#40
|
|
|
Member ![]() ![]() Group: Members Posts: 24 Joined: 28-June 08 Member No.: 219,148 |
Hi Billy,
Here's the log from OTMoveIt2:
Unfortunately, this control is also blocked because Windows can't verify the publisher of the control -- it shows up as "Unknown Publisher". I'm attaching a screen shot of the dialog. this is the same dialog that pops up with eset's control. And interestingly Iit pops up whenever I install anything (like Deckert's, OTmoveit, HiJackThis, and so on). I think Kaspersky runs because it's Java not ActiveX. What do you think? I can install the 30-day trial of eset's scanner if you think that will be beneficial. best, Frito This post has been edited by capt.frito: Aug 7 2008, 11:15 PM
Attached File(s)
|
|
|
|
Aug 8 2008, 02:47 PM
Post
#41
|
|
|
Multi Megaton Malware Munition ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 4,882 Joined: 17-January 08 From: Northfield, Ohio Member No.: 184,215 |
Hello, capt.frito.
Alright... I think at this point you are malware free. I usually like to check with another scanner other than Kaspersky before things are all said and done, but you should be okay. I think dealing with installation of ESET would be overkill in this case This issue with ActiveX controls is something I honestly don't know how to fix. You should start a topic in the Windows XP Home and Professional forum and they will better be able to help you. You can reach that here: http://www.bleepingcomputer.com/forums/forum56.html You now appear to be clean. Congratulations! We need to clean up our tools.
The infections you had were "Basesrv infection" Below are some steps to follow in order to dramatically lower the chances of reinfection. You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented.
Billy3 -------------------- The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
|
|
|
|
Aug 10 2008, 02:03 PM
Post
#42
|
|
|
Multi Megaton Malware Munition ![]() ![]() ![]() ![]() ![]() ![]() Group: HJT Team Posts: 4,882 Joined: 17-January 08 From: Northfield, Ohio Member No.: 184,215 |
Hello, capt.frito.
Since this issue appears resolved, this topic has been closed. If you need this topic reopened, please send me or another moderator a PM. Everyone else please begin a new topic. Billy3 -------------------- The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 23rd November 2008 - 08:01 AM |