Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Antivirus System Pro - trojan


  • This topic is locked This topic is locked
7 replies to this topic

#1 captain chaos 3037

captain chaos 3037

  • Members
  • 37 posts
  • OFFLINE
  •  
  • Local time:03:36 PM

Posted 02 June 2009 - 02:36 PM

Bogus Antivirus System Pro virus
Please note: I attempted to run HijackThis and it will not run in either normal or safe mode.

I have the Antivirus System Pro trojans. A bogus program runs from the system tray, alerts pop up warning me of fake virus attacks and Windows Security alerts pop up.

Also, I can't get HijackThis to run.
_____________________________________

DDS (Ver_09-05-14.01) - NTFSx86
Run by s2 Owner at 14:28:21.64 on Tue 06/02/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1.#QNAN.1134 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:WINDOWSsystem32svchost -k DcomLaunch
C:WINDOWSsystem32svchost -k rpcss
C:WINDOWSSystem32svchost.exe -k netsvcs
C:WINDOWSsystem32svchost.exe -k NetworkService
C:WINDOWSsystem32svchost.exe -k LocalService
C:WINDOWSExplorer.EXE
C:Program FilesLavasoftAd-AwareAAWService.exe
C:WINDOWSsystem32ctfmon.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:PROGRA~1AVGAVG8avgwdsvc.exe
svchost.exe "C:WINDOWSsystem32adsmsexts.exe"
C:Program FilesCommon FilesMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32RioMSC.exe
C:Program FilesAlcohol SoftAlcohol 120StarWindStarWindService.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSsystem32svchost.exe -k imgsvc
C:PROGRA~1AVGAVG8avgrsx.exe
C:WINDOWSsystem32wbemwmiprvse.exe
C:WINDOWSRTHDCPL.EXE
C:WINDOWSsystem32RUNDLL32.EXE
C:PROGRA~1AVGAVG8avgtray.exe
C:Program FilesLavasoftAd-AwareAAWTray.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:WINDOWSSystem32svchost.exe -k HTTPFilter
C:PROGRA~1MICROS~2OFFICE11OUTLOOK.EXE
C:Program FilesAVGAVG8avgcsrvx.exe
C:Program FilesMicrosoft OfficeOFFICE11WINWORD.EXE
C:Program FilesAVGAVG8avgcsrvx.exe
C:Program FilesLavasoftAd-AwareAd-Aware.exe
C:Program FilesSpyware DoctorpctsGui.exe
C:Program FilesSpyware DoctorpctsAuxs.exe
C:Program FilesSpyware DoctorpctsSvc.exe
C:Program FilesSpyware DoctorpctsTray.exe
C:DOCUME~1S2OWNE~1LOCALS~1Tempwinamp.exe
C:DOCUME~1S2OWNE~1LOCALS~1Templogin.exe
C:Program FilesInternet ExplorerIexplore.exe
C:Documents and Settingss2 OwnerMy Documentsdds.scr
C:WINDOWSsystem32wbemwmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mWinlogon: Userinit=c:windowssystem32userinit.exe
BHO: c:windowssystem32yhafd78auhd.dll: {c6c7b2a1-00f3-42bd-f434-00aaba2c8953} - c:windowssystem32yhafd78auhd.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll
uRun: [ctfmon.exe] c:windowssystem32ctfmon.exe
uRun: [SUPERAntiSpyware] c:program filessuperantispywareSUPERAntiSpyware.exe
uRun: [<NO NAME>] c:windowstempj37fklr9e.exe
uRun: [nzdflkioezncfiunfindiuchiuenfcdc] c:windowstempj37fklr9e.exe
uRun: [s2 Owner] c:documents and settingss2 owners2 Owner.exe /i
uRun: [12ZFG94-F641-2SF-K31P-5N1ER6H6L2] c:recyclers-1-5-21-6819749298-3384960927-258564534-3418service.exe
uRun: [reader_s] c:documents and settingss2 ownerreader_s.exe
uRun: [Windows System Recover!] c:docume~1s2owne~1locals~1templogin.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SkyTel] SkyTel.EXE
mRun: [NvCplDaemon] RUNDLL32.EXE c:windowssystem32NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:windowssystem32NvMcTray.dll,NvTaskbarInit
mRun: [AVG8_TRAY] c:progra~1avgavg8avgtray.exe
mRun: [QuickTime Task] "c:program filesquicktimeqttask.exe" -atboottime
mRun: [Ad-Watch] c:program fileslavasoftad-awareAAWTray.exe
mRun: [TkBellExe] "c:program filescommon filesrealupdate_obrealsched.exe" -osboot
mRun: [reader_s] c:windowssystem32reader_s.exe
mRun: [ISTray] "c:program filesspyware doctorpctsTray.exe"
StartupFolder: c:documents and settingss2 ownerstart menuprogramsstartupasgupd32.exe
StartupFolder: c:documents and settingss2 ownerstart menuprogramsstartupfmnupd32.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: Append to existing PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:program filesadobeacrobat 8.0acrobatAcroIEFavClient.dll/AcroIECapture.html
IE: Download &Flash Movies
IE: E&xport to Microsoft Excel - c:progra~1micros~2office11EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:program filescommon filessourcetecswf catcherInternetExplorer.htm
IE: {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - c:program filescommon filessourcetecswf catcherInternetExplorer.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:program filesmessengermsmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC} - c:program filesjavajre1.6.0_02binssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:progra~1micros~2office11REFIEBAR.DLL
Trusted Zone: latitudehosted.comwww
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://play.battlefield-heroes.com/static/updater/BFHUpdater_4.0.15.0.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
TCP: {4CB70CED-9336-44F3-A00A-9966FC24948B} = 24.196.64.53,68.115.71.53
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:program filesavgavg8avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:progra~1common~1skypeSKYPE4~1.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
STS: c:windowssystem32yhafd78auhd.dll: {c6c7b2a1-00f3-42bd-f434-00aaba2c8953} - c:windowssystem32yhafd78auhd.dll

================= FIREFOX ===================

FF - ProfilePath -

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:windowssystem32driversLbd.sys [2009-3-31 64160]
R0 PCTCore;PCTools KDS;c:windowssystem32driversPCTCore.sys [2009-6-2 130936]
R1 avgldx86;AVG Free AVI Loader Driver x86;c:windowssystem32driversavgldx86.sys [2009-1-23 325896]
R1 avgmfx86;AVG Free On-access Scanner Minifilter Driver x86;c:windowssystem32driversavgmfx86.sys [2009-1-23 27784]
R2 avg8wd;AVG Free8 WatchDog;c:progra~1avgavg8avgwdsvc.exe [2009-2-6 298776]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:program fileslavasoftad-awareAAWService.exe [2009-3-9 1005904]
R2 sdAuxService;PC Tools Auxiliary Service;c:program filesspyware doctorpctsAuxs.exe [2009-6-2 348752]
R2 sdCoreService;PC Tools Security Service;c:program filesspyware doctorpctsSvc.exe [2009-6-2 1095560]
S1 SASDIFSV;SASDIFSV;??c:program filessuperantispywaresasdifsv.sys --> c:program filessuperantispywareSASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;??c:program filessuperantispywaresaskutil.sys --> c:program filessuperantispywareSASKUTIL.sys [?]
S2 BRA_Scheduler;Brother BRAdminPro Scheduler;c:program filesbrotherbradmin professional 3bratimer.exe [2008-9-23 65536]
S2 comsysappaudiosrv;COM+ System Application comsysappAudioSrv;c:windowssystem32adsmsexts.exe srv --> c:windowssystem32adsmsexts.exe srv [?]
S2 netsik;netsik;c:windowssystem32driversnetsik.sys [2004-8-3 30976]
S2 PNUpdate;Provision Networks Update Service;c:windowssystem32pnupdate.exe -run --> c:windowssystem32PNUpdate.exe -RUN [?]
S3 SASENUM;SASENUM;??c:program filessuperantispywaresasenum.sys --> c:program filessuperantispywareSASENUM.SYS [?]

=============== Created Last 30 ================

2009-06-02 12:50 464 a---h--- C:aaw7boot.cmd
2009-06-02 12:23 159,600 a------- c:windowssystem32driverspctgntdi.sys
2009-06-02 12:22 130,936 a------- c:windowssystem32driversPCTCore.sys
2009-06-02 12:22 73,840 a------- c:windowssystem32driversPCTAppEvent.sys
2009-06-02 12:22 64,392 a------- c:windowssystem32driverspctplsg.sys
2009-06-02 12:22 <DIR> --d----- c:program filescommon filesPC Tools
2009-06-02 12:22 <DIR> --d----- c:program filesSpyware Doctor
2009-06-02 12:22 <DIR> --d----- c:docume~1s2owne~1applic~1PC Tools
2009-06-02 12:22 <DIR> --d----- c:docume~1alluse~1applic~1PC Tools
2009-06-01 19:18 32 a--s---- c:windowssystem323841160618.dat
2009-06-01 19:18 51,712 ---shr-- c:windowssystem32adsmsexts.exe
2009-06-01 19:18 <DIR> --d----- c:windowssystem32sysloc
2009-06-01 19:17 96,076 a------- c:windowssystem32driversd2402503.sys
2009-06-01 19:17 15,000 a------- c:windowssystem32fgddferdd.dll
2009-06-01 19:17 15,000 a------- c:windowssystem32yhafd78auhd.dll
2009-06-01 14:59 <DIR> --d----- c:program filesZip and Split
2009-06-01 13:53 1,134,592 a------- C:m&i inventory-seconds-0509.xls
2009-06-01 13:53 15,872 a------- C:m&i remit generator-seconds-0509.xls
2009-06-01 13:53 149,504 a------- C:m&i inventory-firsts-0509.xls
2009-06-01 13:53 7,168 a------- C:m&i remit generator-firsts-0509.xls
2009-05-12 18:09 <DIR> --d----- c:program filesPopCap Games

==================== Find3M ====================

2009-06-01 19:21 30,976 a------- c:windowssystem32driversnetsik.sys
2009-06-01 19:17 182,912 a------- c:windowssystem32driversndis.sys
2009-05-26 16:46 15,688 a------- c:windowssystem32lsdelete.exe
2009-05-16 01:48 325,896 a------- c:windowssystem32driversavgldx86.sys
2009-05-16 01:48 11,952 a------- c:windowssystem32avgrsstx.dll
2009-04-21 16:45 64,160 a------- c:windowssystem32driversLbd.sys
2008-03-27 13:31 32 a------- c:docume~1alluse~1applic~1ezsid.dat
2008-02-12 10:33 96 a--sh--- c:windowssystem32MS3F0A.drv

============= FINISH: 14:31:57.45 ===============




Any help would be very, very much appreciated.

Scott

Sorry...meant added DDS.scr logs, not Silent Runnings.

Also...running Ad-Aware and Spyware Doctor:

Win32TrojanTDSS - propagating the same .dll files
Adware.Zeno_Search_Assistant
Backdoor.Hupigon

Hope that helps

Merged 3 posts. ~ OB

Attached Files


Edited by Orange Blossom, 02 June 2009 - 06:26 PM.


BC AdBot (Login to Remove)

 


#2 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,785 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:10:36 PM

Posted 03 June 2009 - 06:58 AM

Hello and welcome to the BleepingComputer.com! :thumbup2:

I will be helping you today and post back with some instructions soon. :)

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. By doing this and then choosing Immediate E-Mail notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.


Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

regards _temp_

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#3 captain chaos 3037

captain chaos 3037
  • Topic Starter

  • Members
  • 37 posts
  • OFFLINE
  •  
  • Local time:03:36 PM

Posted 03 June 2009 - 08:02 AM

I'm ready whenever you are. Thanks _temp_. I have to admit the name _temp_ is a little unnerving though. ;)

Scott

#4 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,785 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:10:36 PM

Posted 03 June 2009 - 08:18 AM

Hi there,

I have bad news for you. :thumbup2:

Your system is infected with a nasty variant of Virut, a polymorphic file infector with IRCBot functionality which infects .exe, .scr files, downloads more malicious files to your system, and opens a back door that compromises your computer. According to this Norman White Paper Assessment of W32/Virut, some variants can infect the HOSTS file and block access to security related web sites. Virux is an even more complex file infector which can embed an iframe into the body of web-related files and infect script files (.php, .asp, and .html). When Virut creates infected files, it also creates non-functional files that are corrupted beyond repair. In many cases the infected files cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files become corrupted and the system may become irreparable.

The virus has a number of bugs in its code, and as a result it may misinfect a proportion of executable files....some W32/Virut.h infections are corrupted beyond repair.

McAfee Risk Assessment and Overview of W32/Virut

There are bugs in the viral code. When the virus produces infected files, it also creates non-functional files that also contain the virus...Due to the damaged caused to files by virut it's possible to find repaired but corrupted files. They became corrupted by the incorrect writing of the viral code during the process of infection. undetected, corrupted files (possibly still containing part of the viral code) can also be found. this is caused by incorrectly written and non-function viral code present in these files.

AVG Overview of W32/VirutThis kind of infection is contracted and spread by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and an increasing source of system infection. However, the CA Security Advisor Research Blog says they have found MySpace user pages carrying the malicious Virut URL. Either way you can end up with a computer system so badly damaged that recovery is not possible and it cannot be repaired. When that happens there is nothing you can do besides reformatting and reinstalling the OS.

...warez and crack web pages are being used by cybercriminals as download sites for malware related to VIRUT and VIRUX. Searches for serial numbers, cracks, and even antivirus products like Trend Micro yield malcodes that come in the form of executables or self-extracting files...quick links in these sites also lead to malicious files. Ads and banners are also infection vectors...

Keygen and Crack Sites Distribute VIRUX and FakeAV

If your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read:There is no guarantee this infection can be completely removed. In some instances it may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Reinstalling Windows without first wiping the entire hard drive with a repartition and/or format will not remove the infection. The reinstall will only overwrite the Windows files. Any malware on the system will still be there afterwards. Please read:If you still have questions please post them here, I'll be happy to answer. :)

regards _temp_

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#5 captain chaos 3037

captain chaos 3037
  • Topic Starter

  • Members
  • 37 posts
  • OFFLINE
  •  
  • Local time:03:36 PM

Posted 03 June 2009 - 08:43 AM

So it's a lost cause for sure? Your assessment is to wipe the drive?

How much backup data can I take and make sure it's clean?

Thanks.

#6 myrti

myrti

    Sillyberry


  • Malware Study Hall Admin
  • 33,785 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:At home
  • Local time:10:36 PM

Posted 03 June 2009 - 12:32 PM

Heya Captain,

So it's a lost cause for sure?

Yes pretty much so. I would definitely advise to reformat

How much backup data can I take and make sure it's clean?


You can back up all your important documents, personal data files, photos to a CD or DVD drive, not a flash drive or external hard drive as they may become compromised in the process. The safest practice is not to backup any executable files (*.exe), screensavers (*.scr), autorun (.ini) or script files (.php, .asp, and .html) files because they may be infected by malware. Avoid backing up compressed files (.zip, .cab, .rar) that have executable files inside them as some types of malware can penetrate and infect .exe files within compressed files too. Other types of malware may even disguise itself by adding and hiding its extension to the existing extension of file(s) so be sure you look closely at the full file name. After reformatting, scan the backed up data with your anti-virus prior to to copying it back to your hard drive.

regards _temp_

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!

animinionsmalltext.gif

Follow BleepingComputer on: Facebook | Twitter | Google+


#7 captain chaos 3037

captain chaos 3037
  • Topic Starter

  • Members
  • 37 posts
  • OFFLINE
  •  
  • Local time:03:36 PM

Posted 03 June 2009 - 01:08 PM

Thanks for the help. Go ahead and close this thread then. Have a good one.

Cheers,
Scott

#8 kahdah

kahdah

  • Security Colleague
  • 11,138 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Florida
  • Local time:04:36 PM

Posted 03 June 2009 - 06:14 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :thumbup2:

If your the topic starter, and need this topic reopened, please contact me via pm with the address of the thread.

Everyone else please begin a New Topic.
Please do not pm for help, post it in the forums instead.

If I am helping you and have not responded for 48 hours please send me a pm as I don't always get notifications.

My help is always free, however, if you would like to make a donation to me for the help I have provided please click here Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users