---
Patient is Samsung NP-N150 running Windows 7 Starter with disabled Norton Internet Security Netbook Edition (ver 17.9.0.12) and outdated Avira AntiVir Personal - Free Antivirus (ver 10.2.0.704)
Symptoms:
- cant connect to internet
- recurring 30 pop-ups showing various "failed to write all the components for the file \\system32"
- can not access folders via windows explorer
- "seemingly" missing files
- recuring fake error messages like "Critical Error! HDD clusters are partly damaged. Segment load failure" "Critical Error! RAM memory usage is critically high. RAM memory failure." "Critical Error! Windows OS can’t detect a free hard disk space. HDD error"
Troubleshooting attempts:
- ran several scans with Avira and found
- TR/Crypt.XPACK.Gen2.Trojan in several exe files like C:\ProgramData\okELbvLNiIYhrc.exe and C:\ProgramData\g33dm0Lq3mSdJt.exe
- contains recognition pattern of the HTML/Infected.Webpage.Gen HTML script virus in C:\Users\username\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5
- installed and ran several scans with MBAM and found recurring Hijack.StartMenu
- finally, I installed and scanned with ComboFix and this is the log
combofix_log_11-15-11.txt (13.53K)
Number of downloads: 0
---
ComboFix 11-11-14.02 - Yolet 11/15/2011 6:17.1.2 - x86
Microsoft Windows 7 Starter 6.1.7600.0.1252.63.1033.18.1013.434 [GMT 8:00]
Running from: E:\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
AV: Norton Internet Security Netbook Edition *Disabled/Outdated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security Netbook Edition *Disabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: AntiVir Desktop *Enabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Norton Internet Security Netbook Edition *Disabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\CweHcQeaJGeQA.exe
c:\programdata\FullRemove.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-10-14 to 2011-11-14 )))))))))))))))))))))))))))))))
.
.
2011-11-14 22:38 . 2011-11-14 22:39 -------- d-----w- c:\users\Yolet\AppData\Local\temp
2011-11-14 22:38 . 2011-11-14 22:38 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-11-14 14:44 . 2011-11-14 14:44 56200 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C9F909AC-F25B-4230-893F-56E7C3B6F2FA}\offreg.dll
2011-11-14 14:41 . 2011-11-14 14:41 63115 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2011-11-14 14:41 . 2011-11-14 14:41 4599 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UIRESOURCE.JS
2011-11-14 14:41 . 2011-11-14 14:41 6429 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2011-11-14 14:41 . 2011-11-14 14:41 8646 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2011-11-14 14:41 . 2011-11-14 14:41 9310 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2011-11-14 14:41 . 2011-11-14 14:41 5927 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2011-11-14 14:41 . 2011-11-14 14:41 8613 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\SAVEDUSER.JS
2011-11-14 14:41 . 2011-11-14 14:41 1651 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\QUERYSTRING.JS
2011-11-14 14:41 . 2011-11-14 14:41 6910 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\NEWUSERCOMM.JS
2011-11-14 14:41 . 2011-11-14 14:41 18541 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LOCALIZATION.JS
2011-11-14 14:41 . 2011-11-14 14:41 6208 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\LINK.JS
2011-11-14 14:41 . 2011-11-14 14:41 8288 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\IMAGE.JS
2011-11-14 14:40 . 2011-11-14 14:40 51852 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\EXTERNALWRAPPER.JS
2011-11-14 14:40 . 2011-11-14 14:40 20719 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\DIVWRAPPER.JS
2011-11-14 14:40 . 2011-11-14 14:40 23327 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\COMBOBOX.JS
2011-11-14 14:40 . 2011-11-14 14:40 7271 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\CHECKBOX.JS
2011-11-14 14:40 . 2011-11-14 14:40 8782 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\BUTTON.JS
2011-11-14 10:59 . 2011-11-14 10:59 -------- d--h--w- c:\users\Yolet\AppData\Roaming\Malwarebytes
2011-11-14 10:59 . 2010-11-29 09:42 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-14 10:59 . 2011-11-14 10:59 -------- d--h--w- c:\programdata\Malwarebytes
2011-11-14 10:59 . 2010-11-29 09:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-14 10:59 . 2011-11-14 10:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-12 08:46 . 2011-10-07 03:48 6668624 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{C9F909AC-F25B-4230-893F-56E7C3B6F2FA}\mpengine.dll
2011-11-11 04:19 . 2011-09-29 15:43 1285488 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-11-10 13:56 . 2011-09-29 04:20 2339840 ----a-w- c:\windows\system32\win32k.sys
2011-11-10 13:50 . 2011-10-01 04:43 708608 ----a-w- c:\program files\Common Files\System\wab32.dll
2011-11-07 02:44 . 2011-11-14 04:00 -------- d--h--w- c:\users\Yolet\AppData\Local\Windows Live Writer
2011-11-07 02:44 . 2011-11-07 02:44 -------- d--h--w- c:\users\Yolet\AppData\Roaming\Windows Live Writer
2011-11-01 03:04 . 2011-11-01 03:04 -------- d--h--w- c:\users\Yolet\AppData\Local\CrashDumps
2011-10-27 15:51 . 2011-10-27 15:53 -------- d--h--w- c:\users\Yolet\AppData\Local\Facebook
2011-10-26 03:17 . 2011-08-15 04:25 6144 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2011-10-20 14:22 . 2011-08-17 04:22 75776 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-20 14:22 . 2011-08-17 04:26 465408 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-20 14:22 . 2011-08-17 04:22 72704 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-20 14:22 . 2011-08-17 04:22 59904 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-20 14:22 . 2011-08-17 04:22 204288 ----a-w- c:\windows\system32\MSNP.ax
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-13 00:27 . 2011-01-03 08:47 66616 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-11-13 00:27 . 2011-01-03 08:47 138192 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-08-27 04:43 . 2011-10-15 08:28 571904 ----a-w- c:\windows\system32\oleaut32.dll
2011-08-27 04:43 . 2011-10-15 08:28 233472 ----a-w- c:\windows\system32\oleacc.dll
2011-08-22 02:53 . 2011-10-15 07:59 340088 ----a-w- c:\windows\system32\drivers\NIS\1109000.00C\symtdiv.sys
2011-08-22 02:53 . 2011-10-15 07:59 173176 ----a-w- c:\windows\system32\drivers\NIS\1109000.00C\symefa.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\Yolet\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2011-10-27 137536]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-04-07 8555040]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2010-03-25 1891720]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Norton Online Backup"="c:\program files\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-01 966488]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-18 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-18 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-18 150552]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2009-05-19 222504]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-01-03 281768]
"Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-11-29 963976]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-4-7 828704]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 Autorun CDROM Monitor;Autorun CDROM Monitor;c:\windows\system32\SupportAppXL\cdrom_mon.exe [2009-01-09 81920]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DCService.exe;DCService.exe;c:\programdata\DatacardService\DCService.exe [2010-05-08 229376]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2010-04-30 206336]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1109000.00C\SYMDS.SYS [2009-10-15 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1109000.00C\SYMEFA.SYS [2011-08-22 173176]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20110225.002\BHDrvx86.sys [2011-02-25 800376]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1109000.00C\ccHPx86.sys [2011-08-04 485512]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20110308.003\IDSvix86.sys [2010-11-30 353912]
S1 SABI;SAMSUNG Kernel Driver For Windows 7;c:\windows\system32\Drivers\SABI.sys [2009-05-28 10752]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1109000.00C\Ironx86.SYS [2010-04-29 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NIS\1109000.00C\SYMTDIV.SYS [2011-08-22 340088]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2011-11-13 136360]
S2 cvhsvc;Client Virtualization Handler;c:\program files\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 821664]
S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe [2011-08-04 126400]
S2 NOBU;Norton Online Backup;c:\program files\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [2010-09-13 508264]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys [2010-03-06 286248]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-02 33320]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-01-09 102448]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys [2010-04-01 109056]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2010-05-22 70656]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys [2010-09-13 577384]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys [2010-09-13 194408]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys [2010-09-13 21864]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys [2010-09-13 19304]
S3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-13 219496]
S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x86.sys [2010-07-08 322336]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2779320541-4068795075-1193535896-1000Core.job
- c:\users\Yolet\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-27 15:51]
.
2011-11-14 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2779320541-4068795075-1193535896-1000UA.job
- c:\users\Yolet\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-10-27 15:51]
.
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{D5F3AA11-42B8-4683-8E85-D8114EEB240B}: NameServer = 202.138.128.50 202.138.128.54
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
HKCU-Run-CweHcQeaJGeQA.exe - c:\programdata\CweHcQeaJGeQA.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.9.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.9.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-11-15 06:49:49
ComboFix-quarantined-files.txt 2011-11-14 22:49
.
Pre-Run: 85,064,720,384 bytes free
Post-Run: 85,443,129,344 bytes free
.
- - End Of File - - F3748109DA01C8B90935381EE0881331
---
As instructed in the thread (http://www.bleepingcomputer.com/forums/topic34773.html), I have the logs for DDS and GMER.
DDS.txt (14.77K)
Number of downloads: 1
Attach.txt (9.03K)
Number of downloads: 0
ark.txt (8.39K)
Number of downloads: 0
This post has been edited by Orange Blossom: 15 November 2011 - 11:39 PM

Help
This topic is locked

Back to top









