Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.
MalwareByte's Anti-Malware Download

Important Announcement: The winners of the BC Million Post contest have been announced. You can read who the winners are at this post.

- BleepingComputer Management

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

3 Pages V  < 1 2 3  
Closed TopicStart new topic
> Klone.t And Basefdrn32.dll, Need help removing this infection, please
Billy O'Neal
post Aug 5 2008, 06:04 PM
Post #31


Multi Megaton Malware Munition
******

Group: HJT Team
Posts: 4,882
Joined: 17-January 08
From: Northfield, Ohio
Member No.: 184,215



Hello, capt.frito.

Yes, I have an idea of what might be going on there smile.gif

Try this:

We need to repair some of windows' internal registration settings
  1. Please download Dial-A-Fix from one of the following mirrors:
  2. Extract the zip file to your desktop.
  3. Double click Dial-a-Fix.exe to start the program.
  4. Press the green double checkmark box (Looks like this: )
  5. UNcheck "Empty Temp Folders", as well as "Adjust Time/Date" in the prep section. The prep section should then look like this:
  6. When the window looks like this, press the GO button in the bottom of the window.
  7. Exit/Close Dial-A-Fix

Billy3


--------------------
The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
Go to the top of the page
 
+Quote Post
capt.frito
post Aug 6 2008, 12:04 AM
Post #32


Member
**

Group: Members
Posts: 24
Joined: 28-June 08
Member No.: 219,148



Hi Billy,

Okay I ran Dial-A-Fix, seemed to run, but still cannot d/l either XP SP3 or the eset.com online scanner. I did reboot a few times, ran Dial-A-Fix a few times...all to no avail.

Any other ideas?
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 6 2008, 12:31 AM
Post #33


Multi Megaton Malware Munition
******

Group: HJT Team
Posts: 4,882
Joined: 17-January 08
From: Northfield, Ohio
Member No.: 184,215



Hello, capt.frito.
You can obtain a stand alone copy of SP3 from here:
http://www.microsoft.com/downloads/details...;displaylang=en

Let's try a different onlinescan. Your system may have been set to block ActiveX Controls which would disable both Windows Update and ESET.

What version of Internet Exploder are you using?

Please do an online scan with Kaspersky WebScanner.
  1. Please visit the Kaspersky Online Scanner website.
    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
  2. Click on the Accept button and install any components it needs.
  3. The program will install and then begin downloading the latest definition files.
  4. After the files have been downloaded on the left side of the page in the Scan section select My Computer
  5. This will start the program and scan your system.
  6. The scan will take a while, so be patient and let it run.
  7. Once the scan is complete, click on View scan report
  8. Now, click on the Save Report as button.
  9. Save the file to your desktop.
  10. Copy and paste that information in your next post.

In your next reply, please include the following:
  • Kaspersky's Log

Billy3


--------------------
The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
Go to the top of the page
 
+Quote Post
capt.frito
post Aug 6 2008, 01:05 AM
Post #34


Member
**

Group: Members
Posts: 24
Joined: 28-June 08
Member No.: 219,148



Hi Billy

This machine has IE7 7.0.5730.11 on it. I used the Windows Update successfully since we've been working together. At some point over the past week it just quit working. I spent some time trying to allow eset.com into a trusted zone with very few restrictions on the site (much more liberal than any other settings I've ever made before). Same with Windows Update.

I'll try the manual patch and see if that gets us back to something better. I did run Kaspersky's earlier too (you can look back through the posts if to see when and where...)

best,
Frito
Go to the top of the page
 
+Quote Post
capt.frito
post Aug 6 2008, 10:23 AM
Post #35


Member
**

Group: Members
Posts: 24
Joined: 28-June 08
Member No.: 219,148



Hi Billy,

Good news, SP3 seems to have fixed the Windows Update problem. I applied the patch manually, then went to the update site and it found an additional high priority patch, downloaded it and applied it just fine. I will reboot and try eset's scanner one more time, and if it works I'll post the log. If not I'll use Kaspersky's and post that instead.

best,
Frito
Go to the top of the page
 
+Quote Post
capt.frito
post Aug 6 2008, 10:46 PM
Post #36


Member
**

Group: Members
Posts: 24
Joined: 28-June 08
Member No.: 219,148



Hi Billy,

Latest update... I have upgraded IE7 to the latest release. It now operates with Windows Update just fine. I now have all the latest patches applied, including SP3 and a few post-SP3 security patches and IE7 security patches.

I tried again to run eset.com's online virus scanner. The trouble is that the box we're rescuing cannot verify the publisher and so Windows refuses to run the ActiveX control. I placed eset.com in the "trusted zone", then set the security to "low" which I believe should allow the control to run, but it still says blocked by Windows because the publisher is unknown. I tried forcing all IE7's settings to "factory default", but still no joy.

Just to make sure it's not a local networking issue, I ran eset's online scanner from my own Windows box. While it gave me some cautions about the ActiveX control, it still recognized the publisher correctly, let me run it, and scanned my machine. (Recall that the machine we're working on belongs to a friend). Also note that my IE7 install is all default settings -- I only use IE for Windows Updates, period. Otherwise it's Firefox (on Windows) plus any number of others on Linux. Anyway, I did not have to anything fancy like making eset.com a trusted site. It just worked. So odds are that it's a problem with the infected machine.

I have just started Kaspersky's, which will have to do until we get the unsigned control issue ironed out. I'll post the log when it completes (i.e., shortly). Any ideas on the unsigned control problem?

best,
Frito
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 6 2008, 11:55 PM
Post #37


Multi Megaton Malware Munition
******

Group: HJT Team
Posts: 4,882
Joined: 17-January 08
From: Northfield, Ohio
Member No.: 184,215



It may be that ESET is down... sometimes things happen smile.gif

That's why we have backup tools smile.gif

Billy3


--------------------
The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
Go to the top of the page
 
+Quote Post
capt.frito
post Aug 7 2008, 10:18 AM
Post #38


Member
**

Group: Members
Posts: 24
Joined: 28-June 08
Member No.: 219,148



Hi Billy

Kaspersky just completed. A further thought on eset.com's scanner -- I don't think that it's a "site down" issue. I ran the scanner on a different machine (on the same network, with the same firewall rules applied to both machines, both XP SP3, same IE7 version) and it ran fine and reported the ActiveX control's publisher correctly. I have tried this over a period of several days.

I have d/l'ed the 30 trial version of their NOD32 AV product. I will install it (first removing AVG) if you think it's a good idea. This PC's owner will have to decide on an AV product anyway, and eset's seems s good as any.

Here's the log:



KASPERSKY ONLINE SCANNER 7 REPORT
Thursday, August 7, 2008
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Thursday, August 07, 2008 04:00:32
Records in database: 1064731
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
E:\
H:\
I:\
J:\
K:\
Scan statistics
Files scanned 85238
Threat name 3
Infected objects 3
Suspicious objects 0
Duration of the scan 02:19:56

File name Threat name Threats count
C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE Infected: not-a-virus:AdWare.Win32.SearchIt.t 1
C:\_OTMoveIt\MovedFiles\07292008_224857\a Infected: Trojan-Downloader.Win32.FraudLoad.bep 1
D:\I386\Apps\APP16455\src\HPSummer2005.exe Infected: not-a-virus:AdWare.Win32.MyWay.j 1
The selected area was scanned.


best,
Frito

Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 7 2008, 08:33 PM
Post #39


Multi Megaton Malware Munition
******

Group: HJT Team
Posts: 4,882
Joined: 17-January 08
From: Northfield, Ohio
Member No.: 184,215



Hello, capt.frito.

I'm not sure why ESET won't run on your system... online scanners can sometimes be very finicky. I want to get rid of those files KAV found and run one more check.. (I'm not so keep on it's detection rate...)

If this comes back clean you should be okay smile.gif

We need to move some files
Please download the OTMoveIt2 by OldTimer.
  1. Save it to your desktop.
  2. Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  3. Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    CODE
    C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE
    D:\I386\Apps\APP16455\src\HPSummer2005.exe

  4. Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
  5. Click the red Moveit! button.
  6. Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  7. Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

We need to run a scan using the F-Secure Online Scanner
  1. Please follow the link to the F-Secure Online Scanner
    Note: This Scanner is for Internet Explorer Only!
  2. Follow the instructions here for installation.
  3. Accept the License Agreement.
  4. Once the ActiveX installs,Click Full System Scan
  5. Once the download completes, the scan will begin automatically.
  6. The scan will take some time to finish, so please be patient.
  7. When the scan completes, click the Automatic cleaning (recommended) button.

In your next reply, please include the following:
  • OTMoveIt2's Log
  • F-Secure OnlineScan's Log

Billy3


--------------------
The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
Go to the top of the page
 
+Quote Post
capt.frito
post Aug 7 2008, 11:13 PM
Post #40


Member
**

Group: Members
Posts: 24
Joined: 28-June 08
Member No.: 219,148



Hi Billy,

Here's the log from OTMoveIt2:


C:\Program Files\Online Services\AOL90US\comps\toolbar\toolbr.EXE moved successfully.
D:\I386\Apps\APP16455\src\HPSummer2005.exe moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08072008_220007


Unfortunately, this control is also blocked because Windows can't verify the publisher of the control -- it shows up as "Unknown Publisher". I'm attaching a screen shot of the dialog. this is the same dialog that pops up with eset's control. And interestingly Iit pops up whenever I install anything (like Deckert's, OTmoveit, HiJackThis, and so on). I think Kaspersky runs because it's Java not ActiveX.

What do you think?

I can install the 30-day trial of eset's scanner if you think that will be beneficial.

best,
Frito

This post has been edited by capt.frito: Aug 7 2008, 11:15 PM

Attached File(s)
Attached File  blocked_ccontrol.jpg ( 21.38k ) Number of downloads: 4
 
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 8 2008, 02:47 PM
Post #41


Multi Megaton Malware Munition
******

Group: HJT Team
Posts: 4,882
Joined: 17-January 08
From: Northfield, Ohio
Member No.: 184,215



Hello, capt.frito.

Alright... I think at this point you are malware free. I usually like to check with another scanner other than Kaspersky before things are all said and done, but you should be okay.

I think dealing with installation of ESET would be overkill in this case smile.gif

This issue with ActiveX controls is something I honestly don't know how to fix.

You should start a topic in the Windows XP Home and Professional forum and they will better be able to help you.
You can reach that here:
http://www.bleepingcomputer.com/forums/forum56.html

You now appear to be clean. Congratulations!

We need to clean up our tools.
  1. Please download OTMoveIt2 by OldTimer and save it to your desktop.
  2. Click the Clean Up button.
  3. Accept any prompts.
  4. This will remove any tools we used, including OTMoveIt, and will require a reboot.
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints: Malware Complaints. Just find your country room and register your complaint.
The infections you had were "Basesrv infection"

Below are some steps to follow in order to dramatically lower the chances of reinfection.
You may have already implemented some of the steps below, however you should follow any steps that you have not already implemented.
  1. Set a New Restore Point to prevent possible reinfection from an old one.
    Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.
    You can view a video of the following instructions.
    • Go to Start > Programs > Accessories > System Tools and click "System Restore".
    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Then go to Start > Run and type: Cleanmgr
    • Click "OK".
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
    Note: You should only do this once!
    spacer.gif
  2. Make sure you install all the security updates for Windows, Internet Explorer & Microsoft Office
    Whenever a security problem in its software is found, Microsoft will usually create a patch for it. After the patch is installed, attackers can't use the vulnerability to install malicious software on your PC, so keeping up with these patches will help to prevent malicious software being installed on your PC
    Go here to check for & install updates to Microsoft applications.
    Note: The update process uses ActiveX, so you will need to use Internet Explorer for it, and allow the ActiveX control that it wants to install.
    spacer.gif
  3. Keep your non-Microsoft applications updated as well
    Microsoft isn't the only company whose products can contain security vulnerabilities, to check for other vulnerable programs running on your PC that are in need of an update, you can use the Secunia Software Inspector - I suggest that you run it at least once a month.
    spacer.gif
  4. Make Internet Explorer more secure
    • Click Start -> Run
    • Type "Inetcpl.cpl" (without quotes) & click OK.
    • Click on the Security tab.
    • Click "Reset all zones to default level"
    • Make sure the Internet Zone is selected & click "Custom level"
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls") to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Click OK, then Apply, then OK to exit the Internet Properties page.
    spacer.gif
  5. Install SpywareBlaster & make sure to update it regularly
    SpywareBlaster sets killbits in the registry to prevent known malicious ActiveX controls from installing themselves on your computer.
    If you don't know what ActiveX controls are, see here
    You can download SpywareBlaster from here.
    spacer.gif
  6. Install and use Spybot Search & Destroy
    Instructions are located here
    Make sure you update, reimmunize & scan regularly.
    spacer.gif
  7. Make use of the HOSTS file included with Spybot Search & Destroy
    Every version of Microsoft Windows includes a hosts file. A hosts file is a bit like a phone book: it points to the actual numeric address (i.e. the IP address) from the human friendly name of a website. This feature can be used to block malicious websites.
    Spybot Search & Destroy has a good HOSTS file built in. To enable it,
    • Run Spybot Search & Destroy
    • Click the Mode button on the toolbar, and then place a tick next to Advanced mode.
    • Click Yes.
    • In the left hand pane of Spybot Search & Destroy, click on "Tools", and then on Hosts File.
    • Click on "Add Spybot-S&D hosts list"
    Note: On some PCs, having a custom HOSTS file installed can cause a significant slowdown. Following these instructions should resolve the issue
    • Click Start -> Run.
    • Type "services.msc" (without quotes) & click OK.
    • In the list, find the service called "DNS Client" & double click on it.
    • On the dropdown box, change the setting from "Automatic" to "Manual".
    • Click OK.
    • Exit/close the Services window
    For a more detailed explanation of the HOSTS file, click here.
    spacer.gif
  8. Install a-squared Free & update and scan with it regularly
    a-squared free is a product from Emsi Software provided free for private use that can detect and remove a variety of malicious software. You can get it here
    Note: If you have a dialup internet connection, you may also like to install a-squared Anti-Dialer which provides some real time protection against premium rate dialers
    spacer.gif
  9. Finally I am trying to make one point very clear. It is absolutely essential to keep all of your security programs up to date!

Billy3


--------------------
The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
Go to the top of the page
 
+Quote Post
Billy O'Neal
post Aug 10 2008, 02:03 PM
Post #42


Multi Megaton Malware Munition
******

Group: HJT Team
Posts: 4,882
Joined: 17-January 08
From: Northfield, Ohio
Member No.: 184,215



Hello, capt.frito.
Since this issue appears resolved, this topic has been closed.

If you need this topic reopened, please send me or another moderator a PM.

Everyone else please begin a new topic.

Billy3


--------------------
The forum is always a busy place. In the event I fail to reply within twenty-four hours, feel free to send me a PM.
Go to the top of the page
 
+Quote Post

3 Pages V  < 1 2 3
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 23rd November 2008 - 08:01 AM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides

© 2003-2008 All Rights Reserved Bleeping Computer LLC.