siberadam
Topic Starter
I recently had to completly re-install xp. For about a week I have installing all my old programs, running updates for windows XP and set up my pc for auto updates and even run the updater anytime i installed something new. Of course the first things I loaded were my virus protector Kaspersky and Firewall sygate….
Today I was updating Windows Media Player and a suggested update was offered when I tried to load a song… it appears to have been a virus or trojan. Kaspersky seemed to have caught it but not before serious damage occurred.
I am unable to access the web, my firewall is completely down. After being unable to re-install my firewall and after accessing the web for fixes I quickly realized I was going to loose access to explorer so I managed to download adware and comodo firewall. When I installed both of them neither one would launch. By this time I could no longer access the web with IE or googles Chrome. Chrome seemed to hang in a bit longer than IE as IE went down pretty fast.
You can see the the programs load in the task manager but something is ending them. I tried a system restore and it only had todays date in bold I couldn't go back any further and the time was just moments ago so no use to me. I created a restore point about 5 days ago… dont know what happened to it as its gone. it also appears explorer is deleting programs out of my task manager. The warning from kaspersky indicates IE is trying to embed other programs. I usually have about 30 items and I am down to 15. I have set the IE priority to low while kaspersky runs… as IE was running at 50%….. I think my registry is slowing being destroyed/deleted. I'm going to attempt to unistall IE and re-install…. I dont know how I will be able to restore the registry.
In the registry sygate, adware and comodo are no where to be found. like they have been deleted. I have scanned with kaspersky but nothing further has been found. Kaspersky still continues to give a pop up "Invader riskware running process IE.exec". See below for kaspersky scan and also posted hijack log…
Please advise…….
Thanks ahead of time!!!!
siberadam
from kaspersky
detected: riskware Invader Running process: C:\Documents and Settings\SiberAdam\My Documents\Downloads\windows_media_update.exe
detected: riskware Invader Running process: C:\WINDOWS\Explorer.EXE
detected: riskware Invader Running process: C:\WINDOWS\explorer.exe
detected: riskware Invader Running process: C:\Program Files\Internet Explorer\iexplore.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\winlogon.exe
deleted: Trojan program Trojan-Downloader.Win32.Clopack.a File: C:\DOCUME~1\SIBERA~1\LOCALS~1\Temp\2.tmp
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:51 PM, on 7/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1292428093-1500820517-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1246643880264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1246755479296
O20 - AppInit_DLLs: C:\WINDOWS\System32\dot3svc32.dll
O20 - Winlogon Notify: 286f18bb638 - C:\WINDOWS\System32\dot3svc32.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
–
End of file - 3560 bytes
Today I was updating Windows Media Player and a suggested update was offered when I tried to load a song… it appears to have been a virus or trojan. Kaspersky seemed to have caught it but not before serious damage occurred.
I am unable to access the web, my firewall is completely down. After being unable to re-install my firewall and after accessing the web for fixes I quickly realized I was going to loose access to explorer so I managed to download adware and comodo firewall. When I installed both of them neither one would launch. By this time I could no longer access the web with IE or googles Chrome. Chrome seemed to hang in a bit longer than IE as IE went down pretty fast.
You can see the the programs load in the task manager but something is ending them. I tried a system restore and it only had todays date in bold I couldn't go back any further and the time was just moments ago so no use to me. I created a restore point about 5 days ago… dont know what happened to it as its gone. it also appears explorer is deleting programs out of my task manager. The warning from kaspersky indicates IE is trying to embed other programs. I usually have about 30 items and I am down to 15. I have set the IE priority to low while kaspersky runs… as IE was running at 50%….. I think my registry is slowing being destroyed/deleted. I'm going to attempt to unistall IE and re-install…. I dont know how I will be able to restore the registry.
In the registry sygate, adware and comodo are no where to be found. like they have been deleted. I have scanned with kaspersky but nothing further has been found. Kaspersky still continues to give a pop up "Invader riskware running process IE.exec". See below for kaspersky scan and also posted hijack log…
Please advise…….
Thanks ahead of time!!!!
siberadam
from kaspersky
detected: riskware Invader Running process: C:\Documents and Settings\SiberAdam\My Documents\Downloads\windows_media_update.exe
detected: riskware Invader Running process: C:\WINDOWS\Explorer.EXE
detected: riskware Invader Running process: C:\WINDOWS\explorer.exe
detected: riskware Invader Running process: C:\Program Files\Internet Explorer\iexplore.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\winlogon.exe
deleted: Trojan program Trojan-Downloader.Win32.Clopack.a File: C:\DOCUME~1\SIBERA~1\LOCALS~1\Temp\2.tmp
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:37:51 PM, on 7/6/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-21-1292428093-1500820517-839522115-1003\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User '?')
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1246643880264
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1246755479296
O20 - AppInit_DLLs: C:\WINDOWS\System32\dot3svc32.dll
O20 - Winlogon Notify: 286f18bb638 - C:\WINDOWS\System32\dot3svc32.dll
O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe
–
End of file - 3560 bytes