Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

xwoarh.sys browser hijacker who knows what else


  • This topic is locked This topic is locked
2 replies to this topic

#1 cculhanepsm

cculhanepsm

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:01:17 AM

Posted 12 October 2009 - 12:38 AM

Hello,

First time poster here. I have tried for a week to fix this and now its time for expert intercession.

It appears both IE and Firefox are hijacked and redirected to find-for-you-service.com.

Additionally, I believe I have something nasty in c:\windows\system32\drivers\xwoarh.sys
All research points to something nasty. I cannot remove, rename or otherwise delete the file, locks up the entire computer when it gets poked.

I have tried all manner of AV scanners and nothing seems to run to completion. They all stop at the system 32 drivers folder. You may evidence of multiple AV software installs and removals.

I cannot run root repeal for the same reason.

the dds log follows.

DDS (Ver_09-09-29.01) - NTFSx86
Run by cliff at 1:05:38.45 on Mon 10/12/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2389 [GMT -4:00]

AV: *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\UPHClean\uphclean.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Hewlett-Packard\hp LaserJet 1160_1320 series\Digital Imaging\bin\hpqnrs08.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\cliff.ECT\Desktop\dds.pif

============== Pseudo HJT Report ===============

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = https://www.google.com/a/eandctech.com/Serv...t<mplcache=2
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
mRun: [SigmatelSysTrayApp] stsystra.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\servic~1.lnk - c:\program files\microsoft sql server\80\tools\binn\sqlmangr.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: microsoft.com\update
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1255047923843
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1254797198875
DPF: {72C23FEC-3AF9-48FC-9597-241A8EBDFE0A} - hxxp://www.trimble.com/datatransfer/v147/isetupml.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} - hxxp://www.installengine.com/engine/isetup.cab
DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-29-0.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\cliff.ect\applic~1\mozilla\firefox\profiles\fh1tl68k.default\
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - plugin: c:\documents and settings\cliff.ect\local settings\application data\google\update\1.2.131.11\npGoogleOneClick5.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 RCFOX;SonicWALL IPsec Driver;c:\windows\system32\drivers\RCFOX.SYS [2008-10-14 86552]
R2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2009-10-5 582992]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2009-10-5 206608]
S0 cerc6;cerc6; [x]
S1 fd415861;fd415861;c:\windows\system32\drivers\fd415861.sys --> c:\windows\system32\drivers\fd415861.sys [?]
S2 xwoarh;xwoarh;c:\windows\system32\drivers\xwoarh.sys [2009-10-5 175616]
S3 rcvpn;SonicWALL VPN Adapter;c:\windows\system32\drivers\rcvpn.sys [2008-10-14 24876]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2009-10-5 206608]
S3 TrmbTS;TrimbleTS Driver (TrmbTS.sys);c:\windows\system32\drivers\TrmbTS.sys [2007-4-4 29184]
S3 TRMUSB5K;Trimble USB GPS Driver;c:\windows\system32\drivers\TRMUSB5K.SYS [2007-4-4 9881]
S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-11-16 1174152]

=============== Created Last 30 ================

2009-10-12 00:49 3,250 a------- c:\windows\system32\wbem\Outlook_01ca4af75d8ded57.mof
2009-10-11 17:45 <DIR> --d----- c:\docume~1\cliff.ect\applic~1\Office Genuine Advantage
2009-10-10 13:42 <DIR> --d----- c:\program files\G Data
2009-10-10 09:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg9
2009-10-10 08:27 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-10-09 19:15 <DIR> --d----- c:\docume~1\cliff.ect\applic~1\Uniblue
2009-10-09 18:56 2,066,432 -c------ c:\windows\system32\dllcache\mstscax.dll
2009-10-09 18:55 2,189,056 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-09 18:55 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-10-09 18:55 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-09 18:55 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-09 18:55 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-10-09 18:55 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2009-10-09 18:01 28,288 ac------ c:\windows\system32\dllcache\xjis.nls
2009-10-09 18:01 156,672 ac------ c:\windows\system32\dllcache\winzm.ime
2009-10-09 18:01 156,672 ac------ c:\windows\system32\dllcache\winsp.ime
2009-10-09 18:01 156,672 ac------ c:\windows\system32\dllcache\winpy.ime
2009-10-09 18:01 79,360 ac------ c:\windows\system32\dllcache\winar30.ime
2009-10-09 18:01 72,704 ac------ c:\windows\system32\dllcache\wingb.ime
2009-10-09 18:01 65,536 ac------ c:\windows\system32\dllcache\winime.ime
2009-10-09 17:59 92,160 ac------ c:\windows\system32\dllcache\evntwin.exe
2009-10-09 17:57 488 a---hr-- c:\windows\system32\logonui.exe.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\WindowsShell.Manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\wuaucpl.cpl.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\sapi.cpl.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\nwc.cpl.manifest
2009-10-09 17:57 749 a---hr-- c:\windows\system32\ncpa.cpl.manifest
2009-10-09 16:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PCDr
2009-10-09 16:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\PC-Doctor
2009-10-09 16:08 <DIR> --d----- c:\program files\Dell Support Center
2009-10-09 16:08 <DIR> --d----- c:\program files\common files\supportsoft
2009-10-08 21:35 171 a------- c:\windows\system32\conf.xml
2009-10-08 21:31 <DIR> --d----- c:\windows\system32\NtmsData
2009-10-08 20:13 520,192 -------- c:\windows\system32\ati2sgag.exe
2009-10-08 19:36 16,535 a----r-- c:\windows\SET72.tmp
2009-10-08 19:36 1,088,840 a----r-- c:\windows\SET66.tmp
2009-10-08 19:36 1,296,669 a----r-- c:\windows\SET63.tmp
2009-10-08 18:51 4,444 a------- c:\windows\system32\pid.PNF
2009-10-08 18:50 7,334 ac------ c:\windows\system32\dllcache\wmerrenu.cat
2009-10-08 18:50 16,535 a----r-- c:\windows\SETDF.tmp
2009-10-08 18:50 1,088,840 a----r-- c:\windows\SETD3.tmp
2009-10-08 18:50 1,296,669 a----r-- c:\windows\SETD0.tmp
2009-10-08 18:50 4,754 a------- c:\windows\setupapi.old
2009-10-08 18:17 <DIR> --d----- c:\program files\CCleaner
2009-10-08 18:11 389,120 a------- c:\windows\system32\CF27903.exe
2009-10-08 17:17 <DIR> a-dshr-- C:\cmdcons
2009-10-08 14:42 <DIR> --d----- c:\windows\Dell
2009-10-08 13:05 <DIR> --d----- c:\docume~1\cliff.ect\applic~1\Malwarebytes
2009-10-08 09:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-07 18:17 <DIR> --d----- c:\documents and settings\cliff.ect\.scribus
2009-10-07 18:17 <DIR> --d----- c:\program files\Scribus 1.3.3.13
2009-10-06 20:32 68,976 a------- c:\windows\system32\drivers\GRD.sys
2009-10-06 20:32 51,784 a------- c:\windows\system32\drivers\GDTdiIcpt.sys
2009-10-06 20:28 53,320 a------- c:\windows\system32\drivers\MiniIcpt.sys
2009-10-06 20:27 27,720 a------- c:\windows\system32\drivers\GDBehave.sys
2009-10-06 20:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\G DATA
2009-10-06 14:07 <DIR> --d----- c:\windows\system32\Dell
2009-10-06 13:46 262,144 a------- c:\windows\system32\default_user_class.dat
2009-10-06 12:41 <DIR> --d----- c:\program files\ACW
2009-10-06 11:40 195,440 -------- c:\windows\system32\MpSigStub.exe
2009-10-05 22:06 <DIR> --d----- c:\program files\UPHClean
2009-10-05 21:54 <DIR> --d----- c:\program files\Windows Installer Clean Up
2009-10-05 21:33 <DIR> --d----- C:\2d684e3926d475e8cc30ab71296d
2009-10-05 19:55 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-10-05 19:55 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-10-05 16:11 206,608 a------- c:\windows\system32\drivers\TMPassthru.sys
2009-10-05 16:11 <DIR> --d----- c:\program files\Trend Micro
2009-10-05 15:27 <DIR> --d----- C:\53d46bf1f8fdf3b8c93a324a
2009-10-05 15:22 <DIR> --dsh--- c:\documents and settings\cliff.ect\IECompatCache
2009-10-05 15:13 <DIR> --d-h--- c:\windows\system32\GroupPolicy
2009-10-05 15:07 <DIR> --d----- c:\documents and settings\cliff.ect\.housecall6.6
2009-10-05 10:33 175,616 a--s---- c:\windows\system32\drivers\xwoarh.sys
2009-10-03 22:19 96,072 a---h--- c:\windows\system32\mlfcache.dat
2009-10-03 13:42 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-10-03 13:42 26,600 a------- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-10-03 13:41 <DIR> --d----- c:\program files\iPod
2009-10-03 13:41 <DIR> --d----- c:\program files\iTunes
2009-10-03 13:41 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-03 13:41 <DIR> --d----- c:\program files\Bonjour
2009-09-15 21:06 31 a------- c:\windows\tgo_v160.ini
2009-09-13 20:52 <DIR> --d----- C:\GRASS-6-SVN

==================== Find3M ====================

2009-10-10 08:36 128,832 a------- c:\windows\system32\GDIPFONTCACHEV1.DAT
2009-10-09 17:56 23,412 a------- c:\windows\system32\emptyregdb.dat
2009-10-07 22:05 411,368 a------- c:\windows\system32\deploytk.dll
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-03 15:07 403,816 a------- c:\windows\system32\OGACheckControl.dll
2009-08-03 15:07 322,928 a------- c:\windows\system32\OGAAddin.dll
2009-08-03 15:07 230,768 a------- c:\windows\system32\OGAEXEC.exe
2009-07-29 00:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 00:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-27 08:20 87,699 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2008-09-24 14:39 88 a--shr-- c:\windows\system32\55D4A5C27A.sys
2008-09-24 14:39 3,452 a--sh--- c:\windows\system32\KGyGaAvL.sys

============= FINISH: 1:05:51.89 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:07:17 AM

Posted 26 October 2009 - 06:32 PM

Hello,

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and
we are trying our best to keep up.

My name is Syler and I will be helping you to solve your Malware issues. If you have since resolved your issues I would appreciate if you
would let me no so I can close this topic, if you still need help please let me no what issues you are still having, in your next reply.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Then please post back here with the following:
  • log.txt
  • info.txt
Thanks

unite.jpg


#3 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:07:17 AM

Posted 30 October 2009 - 09:41 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending me a PM
with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

unite.jpg





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users