Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malwarealarm


  • This topic is locked This topic is locked
2 replies to this topic

#1 nomaltrouble

nomaltrouble

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:04:47 AM

Posted 20 June 2008 - 05:20 PM

Access Is Denied Deleting Winctrl32.dll No Matter What I've Done

I've disabled messenger live.
I've deleted guest accounts
I've deleted all of the malware registry keys with regedit logged on as administrator,
as well as all files that reference malware in the name in any variation as well as
MalwareAlarm.exe
MalwareAlarmSetup[1].exe
autos.exe
infos.exe
proper.exe
winter.exe

I've killed the processes in task manager. "how do you purge these things from memory?"

I've tried cmd prompt changing file attributes on bn*.tmp files, winnt32.dll and winctrl32.dll
I can usually delete the bn*.tmp files but they always come back

I've tried Highjackthis to delete all of the above files on reboot and they always come back .but they always come back on reboot.

I don't understand the syntax of running
cacls *.* /e /t /g everyone:f

on the files to change the permissions so that hasn't worked

I've run creative log tools that hasn't worked to delete the files,

I've tried Move It that hasn't worked either.

this is a Logfile of Trend Micro HijackThis v2.0.2
Can anyone seriously in the know help? I'm not a fan of paying money to delete a virus. This is the 1st one I've not been able to delete manually, My Win XP Pro is NTFS.
Thank You.

Scan saved at 3:16:31 PM, on 6/19/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\V0470Mon.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [V0470Mon.exe] C:\WINDOWS\V0470Mon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe"
O4 - HKCU\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-21-299502267-152049171-1343024091-1003\..\Run: [Creative Live! Cam Manager] "C:\Program Files\Creative\Creative Live! Cam\Live! Cam Manager\CTLCMgr.exe" (User '?')
O4 - HKUS\S-1-5-21-299502267-152049171-1343024091-1003\..\Run: [MsgCenterExe] "C:\Program Files\Common Files\Real\Update_OB\RealOneMessageCenter.exe" -osboot (User '?')
O4 - HKUS\S-1-5-21-299502267-152049171-1343024091-1003\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background (User '?')
O4 - HKUS\S-1-5-21-299502267-152049171-1343024091-1003\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
O4 - S-1-5-21-299502267-152049171-1343024091-1003 Startup: Creative Element Power Tools Startup.lnk = C:\Program Files\Creative Element Power Tools\Startup.exe (User '?')
O4 - Startup: Creative Element Power Tools Startup.lnk = C:\Program Files\Creative Element Power Tools\Startup.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1190222072314
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1213769382660
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15034/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: WinCtrl32 - C:\WINDOWS\SYSTEM32\WinCtrl32.dll
O23 - Service: Alerter Alerterhkmsvc (Alerterhkmsvc) - Unknown owner - .exe (file missing)
O23 - Service: Application Management AppMgmtlanmanserver (AppMgmtlanmanserver) - Unknown owner - C:\WINDOWS\
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Windows Audio AudioSrvhelpsvc (AudioSrvhelpsvc) - Unknown owner - C:\WINDOWS\
O23 - Service: COM+ System Application COMSysAppSysmonLog (COMSysAppSysmonLog) - Unknown owner - C:\WINDOWS\
O23 - Service: Cryptographic Services CryptSvc HotKey Poller (CryptSvc HotKey Poller) - Unknown owner - .exe (file missing)
O23 - Service: DCOM Server Process Launcher DcomLaunchBrowser (DcomLaunchBrowser) - Unknown owner - .exe (file missing)
O23 - Service: DCOM Server Process Launcher DcomLaunchBrowser DcomLaunchBrowserSwPrv (DcomLaunchBrowserSwPrv) - Unknown owner - .exe (file missing)
O23 - Service: DNS Client Dnscacheupnphost (Dnscacheupnphost) - Unknown owner - C:\WINDOWS\
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Fast User Switching Compatibility FastUserSwitchingCompatibilityxmlprov (FastUserSwitchingCompatibilityxmlprov) - Unknown owner - .exe (file missing)
O23 - Service: Human Interface Device Access HidServEventSystem (HidServEventSystem) - Unknown owner - C:\WINDOWS\
O23 - Service: Human Interface Device Access HidServhelpsvc (HidServhelpsvc) - Unknown owner - C:\WINDOWS\
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: NICCONFIGSVC NICCONFIGSVCAudioSrv (NICCONFIGSVCAudioSrv) - Unknown owner - .exe (file missing)
O23 - Service: IPSEC Services PolicyAgentSENS (PolicyAgentSENS) - Unknown owner - C:\WINDOWS\
O23 - Service: IPSEC Services PolicyAgentSENS PolicyAgentSENSAppMgmt (PolicyAgentSENSAppMgmt) - Unknown owner - .exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Remote Registry RemoteRegistrylanmanserver (RemoteRegistrylanmanserver) - Unknown owner - .exe (file missing)
O23 - Service: Remote Procedure Call (RPC) RpcSsTapiSrv (RpcSsTapiSrv) - Unknown owner - C:\WINDOWS\
O23 - Service: Remote Procedure Call (RPC) RpcSsTapiSrv RpcSsTapiSrvmnmsrvc (RpcSsTapiSrvmnmsrvc) - Unknown owner - .exe (file missing)
O23 - Service: Remote Procedure Call (RPC) RpcSsTapiSrv RpcSsTapiSrvWebClient (RpcSsTapiSrvWebClient) - Unknown owner - .exe (file missing)
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Telephony TapiSrvwltrysvc (TapiSrvwltrysvc) - Unknown owner - .exe (file missing)
O23 - Service: Telnet TlntSvrFastUserSwitchingCompatibility (TlntSvrFastUserSwitchingCompatibility) - Unknown owner - .exe (file missing)
O23 - Service: Windows Time W32Timewuauserv (W32Timewuauserv) - Unknown owner - C:\WINDOWS\
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: Intel® PROSet/Wireless SSO Service WLANKEEPERDcomLaunchBrowser (WLANKEEPERDcomLaunchBrowser) - Unknown owner - .exe (file missing)
O23 - Service: Windows Live Setup Service WLSetupSvcAudioSrvhelpsvc (WLSetupSvcAudioSrvhelpsvc) - Unknown owner - .exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: Wireless Zero Configuration WZCSVCMSDTC (WZCSVCMSDTC) - Unknown owner - C:\WINDOWS\
O23 - Service: Wireless Zero Configuration WZCSVCMSDTC WZCSVCMSDTCRasMan (WZCSVCMSDTCRasMan) - Unknown owner - .exe (file missing)

--
End of file - 10682 bytes

Attached Files



BC AdBot (Login to Remove)

 


#2 steamwiz

steamwiz

  • Members
  • 1,039 posts
  • OFFLINE
  •  
  • Local time:11:47 AM

Posted 24 June 2008 - 04:25 PM

Hi

I'll need you to run several programs & post the logs for me ... starting with this :-

1. Download SDFix and save it to your Desktop.

http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

2. Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

3. Reboot into Safe Mode`:-

Reboot into >>>safe mode

4. Open the extracted SDFix folder and double click RunThis.bat to start the script.
Type Y to begin the cleanup process.

It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
Press any Key and it will restart the PC.

When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.

Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
(Report.txt will also be copied to Clipboard ready for posting back on the forum).

Finally paste the contents of the Report.txt back on the forum.

steam
MICROSOFT MVP - Windows Security 2004/9
member of ASAP since 2004
member of U.N.I.T.E

If I have helped you, please consider a small donation to help me continue my online fight in the war against malware Posted Image

#3 steamwiz

steamwiz

  • Members
  • 1,039 posts
  • OFFLINE
  •  
  • Local time:11:47 AM

Posted 24 July 2008 - 04:40 PM

Due to lack of feedback this topic is now closed.

If the original poster would like it re-opened, please send me a PM with a link to this thread.

cheers

steam
MICROSOFT MVP - Windows Security 2004/9
member of ASAP since 2004
member of U.N.I.T.E

If I have helped you, please consider a small donation to help me continue my online fight in the war against malware Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users