Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet Security 2010 Virus


  • This topic is locked This topic is locked
4 replies to this topic

#1 modage

modage

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:07 AM

Posted 04 February 2010 - 07:32 AM

When user got virus, used Spybot and AVG to remove, and when removed user could no longer login (login prompt kept repeating after entering the login details). So XP Pro reload / repair was carried out. Noticed Network connection problem after this. Cannot access websites but can ping any ip / web address.


DDS.TXT:

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 03/02/2010 19:52:41
System Uptime: 02/04/2010 11:16:14 (-1367 hours ago)

Motherboard: | | ALiveNF7G-HD720p....
Processor: AMD Athlon™ 64 X2 Dual Core Processor 4600+ | CPUSocket | 2394/200mhz
Processor: AMD Athlon™ 64 X2 Dual Core Processor 4600+ | CPUSocket | 2394/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 141.469 GiB free.
D: is CDROM ()
E: - No root directory. Drive type could not be determined.
X: is NetworkDisk (*NT5CSC) - 149 GiB total, 141.469 GiB free.

==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

2007 Microsoft Office system
Accounts
Adobe Flash Player ActiveX
Adobe Reader 8.1.2
AVG Free 9.0
Construct
Google Toolbar for Internet Explorer
Malwarebytes' Anti-Malware
Micropay Professional
Microsoft .NET Framework 2.0
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook 2003
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.6)
NVIDIA Drivers
Quickpay to Micropay Professional Migration Utility
R5 DMO
R5 Line 100 Interface
R5 Line 50 Interface
R5 MMS SQL Interface
R5 System Manager
RealPlayer
Realtek High Definition Audio Driver
Sage 50 Accounts
Sage 50 Accounts 2008
Sage Accounts 2007
Sage Accounts ODBC
SetupSBD
SetupSBDDotNetControls
Shadow Copy Client
Spybot - Search & Destroy
WebFldrs XP

==== Event Viewer Messages From Past Week ========

28/01/2010 14:02:53, error: NETLOGON [5719] - No Domain Controller is available for domain BKC due to the following: Not enough storage is available to process this command. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
03/02/2010 20:04:53, error: Dhcp [1002] - The IP address lease 192.168.1.18 for the Network Card with network address 001966623D45 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
03/02/2010 19:49:35, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service SENS with arguments "" in order to run the server: {D3938AB0-5B9D-11D1-8DD2-00AA004ABD5E}
03/02/2010 11:40:33, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips IPSec MRxSmb NetBIOS NetBT Processor RasAcd Rdbss Tcpip WS2IFSL
03/02/2010 11:40:33, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
03/02/2010 11:40:33, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
03/02/2010 11:40:33, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
03/02/2010 11:40:33, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
03/02/2010 11:38:56, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
03/02/2010 11:36:46, error: Service Control Manager [7023] - The Automatic Updates service terminated with the following error: %%2147952506
02/02/2010 12:28:59, error: NETLOGON [3210] - This computer could not authenticate with \\bkc-srvr.bkc.local, a Windows domain controller for domain BKC, and therefore this computer might deny logon requests. This inability to authenticate might be caused by another computer on the same network using the same name or the password for this computer account is not recognized. If this message appears again, contact your system administrator.
02/02/2010 12:27:53, error: NETLOGON [5719] - No Domain Controller is available for domain BKC due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
02/02/2010 12:27:53, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.

==== End Of File ===========================

ATTACH.TXT:


DDS (Ver_09-12-01.01) - NTFSx86
Run by carmel at 12:04:45.17 on 04/02/2010
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1791.1216 [GMT 0:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\carmel.BKC\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\winlogon32.exe,
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar1.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar1.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Zebtab] c:\documents and settings\carmel.bkc\Start Menu/Programs/Zebtab/Zebtab.appref-ms
uRun: [Internet Security 2010] c:\program files\internetsecurity2010\IS2010.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
LSP: c:\windows\system32\helper32.dll
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
Trusted Zone: is-soft-download.com
Trusted Zone: is-software-download.com
Trusted Zone: is-software-download25.com
Trusted Zone: buy-internet-security10.com
Trusted Zone: buy-internetsecurity10.com
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} - hxxp://bkc-srvr/connectcomputer/nshelp.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1205931046953
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\carmel.bkc\applic~1\mozilla\firefox\profiles\ijw26dn1.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-3 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-3 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-3 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-2-3 285392]

=============== Created Last 30 ================

2010-02-04 11:08:36 0 d-----w- c:\docume~1\carmel.bkc\applic~1\Malwarebytes
2010-02-04 10:19:40 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-04 10:19:39 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-04 10:19:39 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-04 10:19:39 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-02-03 19:51:59 79360 -c--a-w- c:\windows\system32\dllcache\phon.ime
2010-02-03 19:50:59 82172 -c--a-w- c:\windows\system32\dllcache\bopomofo.nls
2010-02-03 19:49:04 488 ---ha-r- c:\windows\system32\logonui.exe.manifest
2010-02-03 19:49:00 749 ---ha-r- c:\windows\WindowsShell.Manifest
2010-02-03 19:49:00 749 ---ha-r- c:\windows\system32\wuaucpl.cpl.manifest
2010-02-03 19:49:00 749 ---ha-r- c:\windows\system32\sapi.cpl.manifest
2010-02-03 19:49:00 749 ---ha-r- c:\windows\system32\nwc.cpl.manifest
2010-02-03 19:49:00 749 ---ha-r- c:\windows\system32\ncpa.cpl.manifest
2010-02-03 19:48:44 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2010-02-03 19:48:33 158208 -c--a-w- c:\windows\system32\dllcache\msconfig.exe
2010-02-03 19:37:39 87424 ----a-w- c:\windows\system32\drivers\irda.sys
2010-02-03 19:37:39 8192 ----a-w- c:\windows\system32\wshirda.dll
2010-02-03 19:37:39 27136 ----a-w- c:\windows\system32\irmon.dll
2010-02-03 19:37:39 152576 ----a-w- c:\windows\system32\irftp.exe
2010-02-03 19:29:59 18688 ----a-w- c:\windows\system32\drivers\irsir.sys
2010-02-03 19:28:51 136797 ----a-w- c:\windows\system32\nvapps.nvb
2010-02-03 19:28:23 0 d-----w- c:\windows\NV808956.TMP
2010-02-03 18:42:12 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
2010-02-03 11:35:39 233 ----a-w- c:\windows\wininit.ini
2010-02-03 11:33:02 0 ----a-w- c:\windows\system32\9259.exe
2010-02-03 11:28:12 0 d--h--w- C:\$AVG
2010-02-03 11:27:56 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-03 11:27:56 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-03 11:27:55 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-03 11:27:55 0 d-----w- c:\windows\system32\drivers\Avg
2010-02-03 11:27:39 0 d-----w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-02-03 11:27:20 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-02-03 11:12:57 0 ----a-w- c:\windows\system32\2445.exe
2010-02-03 10:52:51 0 ----a-w- c:\windows\system32\7306.exe
2010-02-03 10:32:45 0 ----a-w- c:\windows\system32\27701.exe
2010-02-03 10:12:29 0 ----a-w- c:\windows\system32\16254.exe
2010-02-03 09:52:14 0 ----a-w- c:\windows\system32\21329.exe
2010-02-03 09:31:59 0 ----a-w- c:\windows\system32\22348.exe
2010-02-03 09:11:44 0 ----a-w- c:\windows\system32\3678.exe
2010-02-03 08:51:29 0 ----a-w- c:\windows\system32\11505.exe
2010-02-03 08:31:13 0 ----a-w- c:\windows\system32\15325.exe
2010-02-03 08:10:58 0 ----a-w- c:\windows\system32\19903.exe
2010-02-03 07:50:42 0 ----a-w- c:\windows\system32\1019.exe
2010-02-03 07:30:27 0 ----a-w- c:\windows\system32\9133.exe
2010-02-03 07:10:12 0 ----a-w- c:\windows\system32\7751.exe
2010-02-03 06:49:57 0 ----a-w- c:\windows\system32\2880.exe
2010-02-03 06:29:41 0 ----a-w- c:\windows\system32\24295.exe
2010-02-03 06:09:26 0 ----a-w- c:\windows\system32\18512.exe
2010-02-03 05:49:11 0 ----a-w- c:\windows\system32\19158.exe
2010-02-03 05:28:55 0 ----a-w- c:\windows\system32\20253.exe
2010-02-03 05:08:40 0 ----a-w- c:\windows\system32\11268.exe
2010-02-03 04:48:25 0 ----a-w- c:\windows\system32\22898.exe
2010-02-03 04:28:10 0 ----a-w- c:\windows\system32\7547.exe
2010-02-03 04:07:54 0 ----a-w- c:\windows\system32\16320.exe
2010-02-03 03:47:39 0 ----a-w- c:\windows\system32\23763.exe
2010-02-03 03:27:24 0 ----a-w- c:\windows\system32\7289.exe
2010-02-03 03:07:09 0 ----a-w- c:\windows\system32\10641.exe
2010-02-03 02:46:54 0 ----a-w- c:\windows\system32\27675.exe
2010-02-03 02:26:39 0 ----a-w- c:\windows\system32\27732.exe
2010-02-03 02:06:24 0 ----a-w- c:\windows\system32\13985.exe
2010-02-03 01:46:09 0 ----a-w- c:\windows\system32\5844.exe
2010-02-03 01:25:53 0 ----a-w- c:\windows\system32\26453.exe
2010-02-03 01:05:38 0 ----a-w- c:\windows\system32\31519.exe
2010-02-03 00:45:23 0 ----a-w- c:\windows\system32\24133.exe
2010-02-03 00:25:07 0 ----a-w- c:\windows\system32\2974.exe
2010-02-03 00:04:52 0 ----a-w- c:\windows\system32\2741.exe
2010-02-02 23:44:37 0 ----a-w- c:\windows\system32\24257.exe
2010-02-02 23:24:22 0 ----a-w- c:\windows\system32\4209.exe
2010-02-02 23:04:07 0 ----a-w- c:\windows\system32\16487.exe
2010-02-02 22:43:52 0 ----a-w- c:\windows\system32\10702.exe
2010-02-02 22:23:36 0 ----a-w- c:\windows\system32\24666.exe
2010-02-02 22:03:21 0 ----a-w- c:\windows\system32\13996.exe
2010-02-02 21:43:05 0 ----a-w- c:\windows\system32\6269.exe
2010-02-02 21:22:49 0 ----a-w- c:\windows\system32\17642.exe
2010-02-02 21:02:34 0 ----a-w- c:\windows\system32\9847.exe
2010-02-02 20:42:19 0 ----a-w- c:\windows\system32\26881.exe
2010-02-02 20:22:04 0 ----a-w- c:\windows\system32\23553.exe
2010-02-02 20:01:49 0 ----a-w- c:\windows\system32\1466.exe
2010-02-02 19:41:34 0 ----a-w- c:\windows\system32\1579.exe
2010-02-02 19:21:19 0 ----a-w- c:\windows\system32\14413.exe
2010-02-02 19:01:03 0 ----a-w- c:\windows\system32\28453.exe
2010-02-02 18:40:47 0 ----a-w- c:\windows\system32\4670.exe
2010-02-02 18:20:26 0 ----a-w- c:\windows\system32\14195.exe
2010-02-02 18:00:05 0 ----a-w- c:\windows\system32\11471.exe
2010-02-02 17:39:44 0 ----a-w- c:\windows\system32\8867.exe
2010-02-02 17:19:23 0 ----a-w- c:\windows\system32\497.exe
2010-02-02 16:59:02 0 ----a-w- c:\windows\system32\10443.exe
2010-02-02 16:38:41 0 ----a-w- c:\windows\system32\25835.exe
2010-02-02 16:18:20 0 ----a-w- c:\windows\system32\31103.exe
2010-02-02 15:58:20 0 ----a-w- c:\windows\system32\311.exe
2010-02-02 15:38:20 0 ----a-w- c:\windows\system32\28170.exe
2010-02-02 15:18:20 0 ----a-w- c:\windows\system32\64.exe
2010-02-02 14:58:19 0 ----a-w- c:\windows\system32\41.exe

==================== Find3M ====================

2010-02-03 19:47:38 22720 ----a-w- c:\windows\system32\emptyregdb.dat
2002-04-16 10:27:54 5 --sha-w- c:\windows\system32\CdI5T.drv
1998-03-20 00:00:00 1048 --sha-w- c:\windows\system32\flfnlf.sys
1998-03-20 00:00:00 1048 --sha-w- c:\windows\system32\rlfnlf.sys
1998-03-20 00:00:00 1048 --sha-w- c:\windows\system32\TMail3FL.SYS
1998-03-20 00:00:00 1048 --sha-w- c:\windows\system32\TMailRL.sys

============= FINISH: 12:04:56.31 ===============




RootRepeal Report:

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2010/02/04 12:12
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xB68EA000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBADD0000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB560C000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\WINDOWS\Prefetch\ROOTREPEAL.EXE-23E775B7.pf
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\sscorlib.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\sscorlib.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\ssfx.UI.Forms.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\ssfx.UI.Forms.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\ssfx.Core.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\ssfx.Core.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\Zebtab.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\carmel.BKC\Local Settings\Apps\2.0\T1G4N3MR.AG2\XWVZ7JO1.L1E\manifests\Zebtab.exe.manifest
Status: Locked to the Windows API!

==EOF==






BC AdBot (Login to Remove)

 


#2 modage

modage
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:07 AM

Posted 04 February 2010 - 08:09 AM

I've also run hijack this, AND noticed the following entry:
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\helper32.dll' missing
but I've searched for helper32.dll on other (WORKING) pc's and can't find this dll?. I also cannot do a hijack this analysis on this pc, cause of lack of internet connection.



The full hijackthis log is as follows:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:57:44, on 04/02/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\winlogon32.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Zebtab] C:\Documents and Settings\carmel.BKC\Start Menu/Programs/Zebtab/Zebtab.appref-ms
O4 - HKCU\..\Run: [Internet Security 2010] C:\Program Files\InternetSecurity2010\IS2010.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\windows\system32\helper32.dll' missing
O15 - Trusted Zone: http://*.buy-internet-security10.com
O15 - Trusted Zone: http://*.buy-internetsecurity10.com
O15 - Trusted Zone: http://*.is-soft-download.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.is-software-download25.com
O15 - Trusted Zone: http://*.buy-internet-security10.com (HKLM)
O15 - Trusted Zone: http://*.buy-internetsecurity10.com (HKLM)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {485D813E-EE26-4DF8-9FAF-DEDF2885306E} (NSHelp Class) - http://bkc-srvr/connectcomputer/nshelp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd...b?1205931046953
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = bkc.local
O17 - HKLM\Software\..\Telephony: DomainName = bkc.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = bkc.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = bkc.local
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6510 bytes




#3 modage

modage
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:01:07 AM

Posted 05 February 2010 - 07:29 AM

I guess when I don't get an answer from the experts!!.. It's time to backup , format and reload sad.gif...
Strange thing with this problem is that when I ping an IP on the net, instead of the usual:

"pinging 123.222.121.234 with 32 bytes of data: .. "

I get instead something like:

"pinging with 32 bytes of data: .. "

(some foreign characters, but not necessarily these exactly, and the rest of the ping info that follows looks fine. I get these weird characters regardless of the address I ping).

Also did this reload fail because the recommended way of dealing with the "Internet Security 2010" spoof from the bleepingcomputer website wasn't properly followed?... hmm.. i.e. Does it work everytime when followed?..

Any ideas?.. or will I proceed with a reload!


===========

Hello

While we understand your frustration at having to wait, please note that Bleeping Computer deals with several hundred requests for assistance such as yours on a daily basis. As a result, our backlog is quite large as are other comparable sites that help others with malware issues. Although our HJT Team members work on hundreds of requests each day, they are all volunteers who work logs when they can and are able to do so. No one is paid by Bleeping Computer for their assistance to our members.

Further, our malware removal staff is comprised of team members with various levels of skill and expertise to deal with thousands of malware variants, some more complex than others. Although we try to take DDS/HJT logs in order (starting with the oldest), it is often the skill level of the particular helper and sometimes the operating system that dictates which logs get selected first. Some infections are more complicated than others and require a higher skill level to remove. Without that skill level attempted removal could result in disastrous results. In other instances, the helper may not be familiar with the operating system that you are using, since they use another. In either case, neither of us want someone to assist you who is not familiar with your issue and attempt to fix it.

We ask that once you have posted your log and are waiting, please DO NOT "bump" your thread or make further replies until it has been responded to by a member of the HJT Team. The reason we ask this or do not respond to your requests is because that would remove you from the active queue that Techs and Staff have access to. The malware staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response, there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond.

That is why I have made an edit to your last post, instead of a reply. Please do not multiple post here, as that only pushes you further down the queue and causes confusion to the staff.

Please be patient. It may take several days, up to more than a week, perhaps less, to get a response but your log will be reviewed and answered as soon as possible. I advise checking your topic once a day for responses as the e-mail notification system is unreliable.

Thank you for understanding.

Elise - forum moderator

Edited by elise025, 05 February 2010 - 09:15 AM.


#4 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:07 AM

Posted 11 February 2010 - 11:52 AM

Hello,

My name is Syler and I will be helping you to solve your Malware issues. If you have since resolved your issues I would appreciate if you
would let me no so I can close this topic, if you still need help please let me no what issues you are still having, in your next reply.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and
we are trying our best to keep up.

  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)


  1. Please download GMER from one of the following locations, and save it to your desktop:
    • Main Mirror
      This version will download a randomly named file (Recommended)
    • Zip Mirror
      This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  2. Disconnect from the Internet and close all running programs, as this process may crash your computer.
  3. Temporarily disable any real-time active protection so your security program drivers will not conflict with gmer's driver.
  4. Double click on Gmer to run it.
  5. Allow the gmer.sys driver to load if asked.
  6. You may see a rootkit warning window, If you do, click No.
  7. Untick the following boxes on the right side of the Gmer screen.
    Sections
    IAT/EAT
    Files
    Show All
  8. Click on and wait for the scan to finish.
  9. If you see a rootkit warning window, click OK.
  10. Push and save the logfile to your desktop.
  11. Copy and Paste the contents of that file in your next post.



Then please post back here with the following:
  • log.txt
  • info.txt
  • Gmer log

Thanks

unite.jpg


#5 syler

syler

  • Malware Response Team
  • 8,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Warrington, UK
  • Local time:01:07 AM

Posted 16 February 2010 - 11:44 AM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending me a PM
with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

unite.jpg





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users