![]() ![]() |
Dec 9 2008, 01:06 PM
Post
#1
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 9-December 08 Member No.: 82,830 Operating System: Windoes XP |
I was recently infected with a virus on my computer (win32/heur). I used AVG and HijackThis to safely (from what I can tell anyhow) clean out most instances of the virus. However, it seems to have also added information to my tcp/ip settings to use a DNS server. I have tried numerous things, but still can not change the 2 IP's that are hard coded there. Can someone pls help? Below are the HijackThis logs (I have bolded what I see to be problematic). Here are the steps I took to try and correct the issue without any luck: 1) Selected all occurences of O17 below and "fix checked" 2) Went to the tcp/ip settings of my Local Area Connection and check off "Obtain DNS server automatically". 3) Re-started my computer 4) Once rebooted, ran "ipconfig /flushdns" 5) Re-started computer again 6) Did another scan with HijackThis, but had exact re-occurrences of O17 below... Any help is appreciated! Thanks in advance. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:03:08 PM, on 12/9/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\AIM6\aim6.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\DAEMON Tools Lite\daemon.exe C:\Program Files\AIM6\aolsoftware.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\cmd.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp /HIDEBL O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {2A9146F3-E5DE-48D8-8B53-E1214450B778} (Generator Class) - http://users.rcn.com/hornms/MachineID.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1219755032718 O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://attwm.webex.com/client/T25L10NSP41E...bex/ieatgpc.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{A78999CA-CB43-42CE-B406-28895F808FD6}: NameServer = 85.255.116.150;85.255.112.24 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.150;85.255.112.24 O17 - HKLM\System\CS3\Services\Tcpip\Parameters: NameServer = 85.255.116.150;85.255.112.24 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.150;85.255.112.24 O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe -- End of file - 5650 bytes |
|
|
|
Dec 9 2008, 04:29 PM
Post
#2
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,249 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate |
Hello niroowns and welcome to the forums here at WTT!
There is a new variant of this Wareout infection that is changing the settings in routers, if present. Do you have a router? If so proceed with the following instructions. If not let me know. Please download Malwarebytes' Anti-Malware from Here or Here Next disconnect your system from the internet, and your router, then… Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. =============================================== Next you must reset the router to its default configuration. This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router. Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds). If you don’t know the router's default password, you can look it up HERE However, if there are other Zlob-infected machines using the same router, they will need to be cleared with the above steps before resetting the router. Otherwise, the malware will simply go back and change the router's DNS settings. You also need to reconfigure any security settings you had in place prior to the reset. Check out this site here for video tutorials on how to properly configure your router's encryption and security settings. You may also need to consult with your Internet service provider to find out which DNS servers your network should be using. Once you have ran Malwarebytes' Anti-Malware on the infected system, and reset the router to its default configuration you can reconnect to the internet, and router. Then return to this site to post your logs. =============================================== Please post the Malwarebytes log and a new HijackThis log, and also let me know how things are running now. |
|
|
|
Dec 14 2008, 08:23 AM
Post
#3
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,249 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate |
Any update here?
|
|
|
|
Dec 14 2008, 10:34 AM
Post
#4
|
|
|
New Member ![]() Group: New Member Posts: 2 Joined: 9-December 08 Member No.: 82,830 Operating System: Windoes XP |
|
|
|
|
Dec 14 2008, 02:05 PM
Post
#5
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,249 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate |
Glad it worked out. You should post the logs and we may want to run another scan or 2 to make sure you are all clean. Absence of symptoms does not always mean a clean PC. Up to you...
|
|
|
|
Dec 19 2008, 02:00 PM
Post
#6
|
|
![]() Anti-Malware Buddha Group: Malware Expert Posts: 5,249 Joined: 22-July 04 From: New England, USA Member No.: 10,811 Operating System: Windows XP Pro SP3 ~ Vista Ultimate SP2 ~ Windows 7 Ultimate |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
8 | Kendo | 2,932 | 27th June 2003 - 11:54 PM Last post by: Galadriel |
|||
![]() |
3 | exposedone | 1,663 | 24th May 2005 - 07:19 PM Last post by: pskelley |
|||
![]() |
5 | -golfer59- | 1,368 | 14th November 2003 - 11:04 AM Last post by: cnm |
|||
![]() |
4 | burnt horns | 1,018 | 15th March 2005 - 07:46 AM Last post by: pskelley |
|||
![]() |
7 | chrose | 1,199 | 13th October 2006 - 02:11 PM Last post by: Micah_6:8 |
|||
|
Time is now: 17th May 2012 - 03:33 AM |