Atreyu
Topic Starter
This is continued from this WTT thread
I do not have an anti-virus installed on this PC, but putting the affected drive in my XP machine, AVG 8.0 did not find anything. I am behind a hardware router, and the XP firewall is on. AFAIK, the Norton Removal Tool removed Norton Internet Security 2007 properly. XP believes the ethernet connection is working properly, and indeed most of the Net is fine. Results from typing 'winipcfg' seem normal.
A few sites do not come up (in either IE or Firefox), including avg.com and microsoft.com. Malware did not alter the hosts file to do this. When I ping microsoft.com or avg.com, I get "ping request could not find host www.microsoft.com. Please check the name and try again." Right now, this machine uses OpenDNS.org's octets for DNS service.
Here is the HijackThis log file (hand typed in Linux, forgive spelling problems):
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:26 PM, on 4/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ssystem32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\DrvLsnr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_0B\realsched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.slashdot.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =.
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
04 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
04 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
04 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
04 - HKLM\..\Run: {TkBellExe] "C:\Program Files\Common Files\Real\Update_0B\realsched.exe" -osboot
04 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
04 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
04 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
04 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - Global StartupL Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
08 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
09 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
09 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-3C9C571A8263} - C:\Program
09 - Extra 'Tools' menuitem: Windows Messenger - {Fb5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmgs.exe
016: - DPFL {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdcommon/download/tgctlcm.cab
016: - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143168165357
016: - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControlClass) - http://update.microsoft.com/microsoftupdat…b?1143237567484
017: - HKLM\System\CCS\Services\Tcpip\..\{D01B88D3-2A16-48BA-BE84-C0A523E5B086}:NameServer - 208.67.222.222,208.67.220.220
023 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
023 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
023 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
024 - Desktop component 0: (no name) - http://profile.ak.facebook.com/profile5/77…718161_8272.jpg
–
End of file - 3764 bytes
If a site can't be reached, it can't be reached in either IE or Firefox. Also it cannot be pinged. If a site can be reached, everything is fine.
I do not have the Admin password to this box (yet), so I cannot install the MS Malicious Software Removal Tool (or various other tools). Also worth noting is that Safe Mode does not work. If you choose Safe Mode, the machine will reboot.
Sysinternals "Process Monitor" will immediately be shut down if started. This may or might not be related to failing to run in Safe Mode.
I could try going to one of those "test my connection" or "what is my IP" sites, but if something was wrong inside my box, I don't know how or even if it would be reflected in the results they show me.
EDIT: I can go to Microsoft.com, avg.com, etc. through an HTTP proxy. If I set up the proxy correctly, I can even submit samples to virusscan.jotti.org (probably another site I can't access the regular way, I'm starting to forget). But because of WGA or ActiveX or whatever, I suspect a proxy wouldn't work to obtain MS Updates, so I really need to find this machine's problem and fix it.
Something's definitely wrong here. Any help is greatly appreciated.
I do not have an anti-virus installed on this PC, but putting the affected drive in my XP machine, AVG 8.0 did not find anything. I am behind a hardware router, and the XP firewall is on. AFAIK, the Norton Removal Tool removed Norton Internet Security 2007 properly. XP believes the ethernet connection is working properly, and indeed most of the Net is fine. Results from typing 'winipcfg' seem normal.
A few sites do not come up (in either IE or Firefox), including avg.com and microsoft.com. Malware did not alter the hosts file to do this. When I ping microsoft.com or avg.com, I get "ping request could not find host www.microsoft.com. Please check the name and try again." Right now, this machine uses OpenDNS.org's octets for DNS service.
Here is the HijackThis log file (hand typed in Linux, forgive spelling problems):
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:26 PM, on 4/18/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\ssystem32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Analog Devices\DrvLsnr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_0B\realsched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.slashdot.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =.
02 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
04 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
04 - HKLM\..\Run: [DrvLsnr] C:\Program Files\Analog Devices\SoundMAX\DrvLsnr.exe
04 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
04 - HKLM\..\Run: {TkBellExe] "C:\Program Files\Common Files\Real\Update_0B\realsched.exe" -osboot
04 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
04 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
04 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
04 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
04 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
04 - Global StartupL Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
08 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
09 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
09 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-3C9C571A8263} - C:\Program
09 - Extra 'Tools' menuitem: Windows Messenger - {Fb5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmgs.exe
016: - DPFL {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdcommon/download/tgctlcm.cab
016: - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1143168165357
016: - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControlClass) - http://update.microsoft.com/microsoftupdat…b?1143237567484
017: - HKLM\System\CCS\Services\Tcpip\..\{D01B88D3-2A16-48BA-BE84-C0A523E5B086}:NameServer - 208.67.222.222,208.67.220.220
023 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
023 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
023 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
024 - Desktop component 0: (no name) - http://profile.ak.facebook.com/profile5/77…718161_8272.jpg
–
End of file - 3764 bytes
If a site can't be reached, it can't be reached in either IE or Firefox. Also it cannot be pinged. If a site can be reached, everything is fine.
I do not have the Admin password to this box (yet), so I cannot install the MS Malicious Software Removal Tool (or various other tools). Also worth noting is that Safe Mode does not work. If you choose Safe Mode, the machine will reboot.
Sysinternals "Process Monitor" will immediately be shut down if started. This may or might not be related to failing to run in Safe Mode.
I could try going to one of those "test my connection" or "what is my IP" sites, but if something was wrong inside my box, I don't know how or even if it would be reflected in the results they show me.
EDIT: I can go to Microsoft.com, avg.com, etc. through an HTTP proxy. If I set up the proxy correctly, I can even submit samples to virusscan.jotti.org (probably another site I can't access the regular way, I'm starting to forget). But because of WGA or ActiveX or whatever, I suspect a proxy wouldn't work to obtain MS Updates, so I really need to find this machine's problem and fix it.
Something's definitely wrong here. Any help is greatly appreciated.