Answers to your tech questions
Computer forums for help with removing malicious software (malware) and improving computer security

Welcome Guest to What the Tech! ( Log In | Register ) We specialize in the removal of malicious software (malware), but here you'll find free help and support for all your tech questions. We invite you to ask questions, share experiences, and learn. Explore our message boards, or register now to post messages of your own. Please Start Here. Register today (registration removes advertising)

3 Pages V   1 2 3 >  
Closed TopicStart new topic
> [Resolved] Wix xp It all started w/ ISM, Then Malware, HJT Log Posted Newbie Here
denise manager
post Jan 3 2008, 09:41 AM
Post #1


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello:

What I got for Christmas was Internet Speed Monitor, Then Malware performing a system scan and more.
Blasted IE6 with Popups and pop unders, asking me to install malware removal from clickspring.net and purity scan. Eventually overload browser and forced restart numerous times. Brought tower to I T friend he installed and ran another AV Program and Then windows would not start at all. Had to use restore point to get xp running again.

Actions and infections:

Antivirus Symantec Client Security 9.0 picked up some of it but left alot behind, Spybot S & D found some more and attempted to fix. MIcrosoft recommended automatic updates and new service pack included IE7 which shutdown my browser when attempting any dowloads. I attempted to use error report log to find problem and attempt fix. AV suggested it to be "Win32.Trats" virus infection has quarantined entries and then Symantec iself would start at startup attempting to be installed by Win Installer.

Current State: I have rolled back IE 7 to IE 6. Have ability to download though New windows in IE still have problems, they open slow or not at all. But was finally able to dowload and install rogue removal kit, HJT Combofix, Rar, ....and other programs. Ran Combofix only and came here, since I was noticing alot of caveats about this program and HJT and others. This site was recommended and I had been reading some of the posts and HJT Logs to se if similar entires and problems to mine were posted by other users.

I am pleased to finally make it here and I am posting the latest HJT next.
Thank you in advance Have a Great day
Denise

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:41:33 AM, on 04/01/08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
c:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qus8.hpwis.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Program Files\Poker.com\poker.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePoker\EmpirePoker.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: AbsolutePoker.com - {EFFF8D47-D060-4108-B761-E8EC86622E56} - C:\Documents and Settings\All Users\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: Poker.com - {6FDD5236-C9F0-49ef-935D-385F5E21991A} - C:\Documents and Settings\Owner\Start Menu\Programs\Poker.com\Poker.com.lnk (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://onecare.live.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.av.aol.com/molbin/shared/m...83/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1198644143593
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.av.aol.com/molbin/shared/m...,20/mcgdmgr.cab
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Compaq Local Alerter (CPQALERT) - Compaq Computer Corporation - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Compaq DMI Web Agent (cpqWebDmi) - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

--
End of file - 6801 bytes


This post has been edited by denise manager: Jan 4 2008, 11:07 AM
Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 10:02 AM
Post #2


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




http://forums.whatthetech.com/WARNING_t86364.html

WARNING !!!

DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.

Combofix changes almost daily to keep up with new infections.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    [list]



After the above.


I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
--------------------------------------------------------------------
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.



Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 11:02 AM
Post #3


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello LD

I appreciate the help.

I attempted instructions as per your response.

Combofix will not run it generates error " Combofix.exe has caused error shlwapi.dll" and wants to send report to microsoft.

I am stuck for the moment

I will await next response

Regards
Denise
Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 11:07 AM
Post #4


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 11:14 AM
Post #5


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Dear LD

Thank you for your help.

I cannot access DR Web Cureit

When I click link a blank window appears and times out, IE hangs

If I right click link to save to desktop

I receive error " connect with server was reset"

Im kinda stuck again.

Regards
Denise

Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 11:21 AM
Post #6


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




  • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.

    QUOTE
    "%userprofile%\desktop\ComboFix.exe" /KillAll

  • Click OK and this will start ComboFix in a special way.
  • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.


Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.

* After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

* Reconnect to the internet

* Post the following logs/Reports:
  • ComboFix.txt
  • Fresh HijackThis log run after all the other tools have performed their cleanup.
Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 11:30 AM
Post #7


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello LD

I attempted instructions and pasted into run box - Combofix window comes up "paused" then generated error "shlwapi.dll"

and closed combofix again.

I am able to get forums here, but thats about it.

Regards
Denise
Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 11:41 AM
Post #8


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




Run windows updates and get IE 7 again.

Then try combofix again
Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 12:57 PM
Post #9


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello LD

Tried to run windows updates...No Luck
missing files again.

IE explorer will not open pages They just appear blank and stall

I can really only get here and a few other places

Regards
Denise
Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 01:02 PM
Post #10


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




You could try System Restore.

1.
Click Start.

2.
Point to All Programs.

3.
Point to Accessories.

4.
Point to System Tools.

5.
Click System Restore.

6.
Follow the instructions on the wizard.

See if you can find a date the the PC worked.
Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 01:47 PM
Post #11


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello LD

OK found restore point and now have IE7 and all windows updates installed.
Took a bit but back here now, and all is ok so far.

Regards
Denise
Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 01:55 PM
Post #12


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.

**Note: In the event you already have Combofix, please delete it from your desktop and download this new version . It is important that it is saved directly to your desktop**
--------------------------------------------------------------------
  • Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • WARNING: IF you have not already done so Combofix will disconnect your machine from the Internet when it starts
  • Please do not re-connect your machine back to the Internet until Combofix has completely finished.

--------------------------------------------------------------------

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 02:06 PM
Post #13


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello LD

ATF dowloaded and worked fine.

Dowloaded combofix and tried to start program.......Got same error as before

Please Advise
Thank you for your help

Regards
Denise
Go to the top of the page
 
+Quote Post
LDTate
post Jan 5 2008, 02:09 PM
Post #14


Forum God
Group Icon

Group: Root Admin
Posts: 40,577
Joined: 23-September 04
From: Missouri, USA
Member No.: 15,276




* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can click next icon next to the files found:
  • If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:

    This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples)
  • After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Go to the top of the page
 
+Quote Post
denise manager
post Jan 5 2008, 04:10 PM
Post #15


Authentic Member
**

Group: Authentic Member
Posts: 50
Joined: 3-January 08
From: fairmont, wv
Member No.: 75,667
Operating System: Windows xp sp2, ***working off old win 98 se laptop too



Hello LDT:

Here is the log you requested from Drweb.


setup.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\SUD4131;Probably BACKDOOR.Trojan;Moved.;
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members: