BA75
Topic Starter
HI
This afternoon while browzing the net, i got the message suddenly that the 'system is infected' and 'SPyware activity is detected'…
When i googled, i saw this very useful link. I followed the steps given in that. It appears that the spyware is now deleted. My taks manager, speakers were not workign before and now it has started working. Also, i dont get the pop ups that spyware activity is detected and i need to update my security tool.
While all these are gone, i am still stuck with my Wall paper. It still says that my system is infected and i am unable to change the wall paper settings. Is there a way to change it?
Thanks a zillion for this solution link. ANy help on removing the wallpaper would be GREATLY appreaciated.
I am posting my logs below
exehelper log
*****************************
exeHelper by Raktor
Build 20091122
Run at 05:34:08 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\Temp\_ex-08.exe
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
*******************************************************************
DDS log
exeHelper by Raktor
Build 20091122
Run at 05:34:08 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\Temp\_ex-08.exe
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
**************************************************************
Attached log
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-11-29.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/25/2009 5:03:08 PM
System Uptime: 11/29/2009 4:06:13 AM (1 hours ago)
Motherboard: Dell Inc. | | 0NF743
Processor: Intel® Core™2 CPU T5500 @ 1.66GHz | Microprocessor | 980/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 24 GiB total, 12.957 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 50 GiB total, 38.604 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
==== System Restore Points ===================
RP1: 11/29/2009 2:54:31 AM - System Checkpoint
==== Installed Programs ======================
32 Bit HP BiDi Channel Components Installer
Adobe Acrobat Connect Add-in
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
ALPS Touch Pad Driver
Broadcom 440x 10/100 Integrated Controller
Citrix Presentation Server Client
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Dell Resource CD
Dell Wireless WLAN Card
DVD Suite
EMC VPN Client 5.0.01.0600
Google Chrome
High Definition Audio Driver Package - KB835221
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
J2SE Development Kit 5.0 Update 7
J2SE Runtime Environment 5.0 Update 7
Java™ 6 Update 17
LG ODD Auto Firmware Update
LiveUpdate 3.1 (Symantec Corporation)
mCore
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Communicator 2007
Microsoft Office Project Standard 2003
Microsoft Office Standard Edition 2003
Microsoft Office Visio Standard 2003
Microsoft redistributable runtime DLLs VS2005(x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
mIWA
mLogView
mMHouse
mPfMgr
mPfWiz
mProSafe
MSN
mSSO
MSXML 6.0 Parser (KB927977)
mWlsSafe
mWMI
mXML
mZConfig
OZ776 SCR CardBus V1.1.3.6
OZ776 SCR CardBus Windows Driver
PowerDVD
PowerProducer
RealPlayer
SAP Front-End
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB950582)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
SigmaTel Audio
Symantec AntiVirus
Update for Windows XP (KB951072-v2)
WebEx
WebFldrs XP
Windows Communication Foundation
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
WinZip
XML Paper Specification Shared Components Pack 1.0
==== Event Viewer Messages From Past Week ========
11/26/2009 6:42:59 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Bluetooth Support Service service to connect.
11/26/2009 6:42:59 AM, error: Service Control Manager [7000] - The Bluetooth Support Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/26/2009 6:41:48 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
11/26/2009 6:41:30 AM, error: NETLOGON [5719] - No Domain Controller is available for domain HCLTECH due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
11/26/2009 4:32:45 AM, error: Dhcp [1002] - The IP address lease 10.7.72.133 for the Network Card with network address 001C26AC9D9E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
11/26/2009 12:38:50 AM, error: Dhcp [1002] - The IP address lease 192.168.1.145 for the Network Card with network address 001C26AC9D9E has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
********************************************************************************
************************
GMER log
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-29 06:16:50
Windows 5.1.2600 Service Pack 3, v.3264
Running: gmer.exe; Driver: C:\DOCUME~1\Bhaskara\LOCALS~1\Temp\awldiuob.sys
—- System - GMER 1.0.15 —-
SSDT 86292A78 ZwAlertResumeThread
SSDT 86290A78 ZwAlertThread
SSDT 85BB7828 ZwAllocateVirtualMemory
SSDT 86228A78 ZwConnectPort
SSDT 86207A78 ZwCreateMutant
SSDT 86291DB8 ZwCreateThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAAC17350]
SSDT 86243CB8 ZwFreeVirtualMemory
SSDT 86201A78 ZwImpersonateAnonymousToken
SSDT 8623CA78 ZwImpersonateThread
SSDT 861FAD70 ZwMapViewOfSection
SSDT 8645F958 ZwOpenEvent
SSDT 8629FAC8 ZwOpenProcessToken
SSDT 86281AC8 ZwOpenThreadToken
SSDT 8625BFC0 ZwQueryValueKey
SSDT 86289AA0 ZwResumeThread
SSDT 86281A90 ZwSetContextThread
SSDT 86281CA0 ZwSetInformationProcess
SSDT 86280BF0 ZwSetInformationThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAAC17580]
SSDT 8623AA78 ZwSuspendProcess
SSDT 8628AA78 ZwSuspendThread
SSDT 8628BE60 ZwTerminateProcess
SSDT 86280A78 ZwTerminateThread
SSDT 86217DC0 ZwUnmapViewOfSection
SSDT 86073A98 ZwWriteVirtualMemory
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdePort0 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdePort1 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [8654F6F2] atapi.sys[.reloc]
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\BTHUSB \Device\00000097 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000099 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
—- Processes - GMER 1.0.15 —-
Process C:\WINDOWS\system32\wuaclt.exe (*** hidden *** ) 3616
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001a6bc4394a
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001a6bc4394a (not active ControlSet)
—- EOF - GMER 1.0.15 —-
This afternoon while browzing the net, i got the message suddenly that the 'system is infected' and 'SPyware activity is detected'…
When i googled, i saw this very useful link. I followed the steps given in that. It appears that the spyware is now deleted. My taks manager, speakers were not workign before and now it has started working. Also, i dont get the pop ups that spyware activity is detected and i need to update my security tool.
While all these are gone, i am still stuck with my Wall paper. It still says that my system is infected and i am unable to change the wall paper settings. Is there a way to change it?
Thanks a zillion for this solution link. ANy help on removing the wallpaper would be GREATLY appreaciated.
I am posting my logs below
exehelper log
*****************************
exeHelper by Raktor
Build 20091122
Run at 05:34:08 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\Temp\_ex-08.exe
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
*******************************************************************
DDS log
exeHelper by Raktor
Build 20091122
Run at 05:34:08 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Killed process winupdate86.exe
Checking for bad files…
Deleting file C:\WINDOWS\system32\41.exe
Deleting file C:\WINDOWS\system32\critical_warning.html
Deleting file C:\WINDOWS\Temp\_ex-08.exe
Deleting file C:\WINDOWS\system32\winupdate86.exe
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
**************************************************************
Attached log
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-11-29.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 3/25/2009 5:03:08 PM
System Uptime: 11/29/2009 4:06:13 AM (1 hours ago)
Motherboard: Dell Inc. | | 0NF743
Processor: Intel® Core™2 CPU T5500 @ 1.66GHz | Microprocessor | 980/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 24 GiB total, 12.957 GiB free.
D: is CDROM ()
E: is FIXED (NTFS) - 50 GiB total, 38.604 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
==== System Restore Points ===================
RP1: 11/29/2009 2:54:31 AM - System Checkpoint
==== Installed Programs ======================
32 Bit HP BiDi Channel Components Installer
Adobe Acrobat Connect Add-in
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.9
ALPS Touch Pad Driver
Broadcom 440x 10/100 Integrated Controller
Citrix Presentation Server Client
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Dell Resource CD
Dell Wireless WLAN Card
DVD Suite
EMC VPN Client 5.0.01.0600
Google Chrome
High Definition Audio Driver Package - KB835221
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software
J2SE Development Kit 5.0 Update 7
J2SE Runtime Environment 5.0 Update 7
Java™ 6 Update 17
LG ODD Auto Firmware Update
LiveUpdate 3.1 (Symantec Corporation)
mCore
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Communicator 2007
Microsoft Office Project Standard 2003
Microsoft Office Standard Edition 2003
Microsoft Office Visio Standard 2003
Microsoft redistributable runtime DLLs VS2005(x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
mIWA
mLogView
mMHouse
mPfMgr
mPfWiz
mProSafe
MSN
mSSO
MSXML 6.0 Parser (KB927977)
mWlsSafe
mWMI
mXML
mZConfig
OZ776 SCR CardBus V1.1.3.6
OZ776 SCR CardBus Windows Driver
PowerDVD
PowerProducer
RealPlayer
SAP Front-End
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB950582)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB960714)
SigmaTel Audio
Symantec AntiVirus
Update for Windows XP (KB951072-v2)
WebEx
WebFldrs XP
Windows Communication Foundation
Windows Imaging Component
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Service Pack 3
WinRAR archiver
WinZip
XML Paper Specification Shared Components Pack 1.0
==== Event Viewer Messages From Past Week ========
11/26/2009 6:42:59 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Bluetooth Support Service service to connect.
11/26/2009 6:42:59 AM, error: Service Control Manager [7000] - The Bluetooth Support Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
11/26/2009 6:41:48 AM, error: DCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {DCBCA92E-7DBE-4EDA-8B7B-3AAEA4DD412B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18). This security permission can be modified using the Component Services administrative tool.
11/26/2009 6:41:30 AM, error: NETLOGON [5719] - No Domain Controller is available for domain HCLTECH due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
11/26/2009 4:32:45 AM, error: Dhcp [1002] - The IP address lease 10.7.72.133 for the Network Card with network address 001C26AC9D9E has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
11/26/2009 12:38:50 AM, error: Dhcp [1002] - The IP address lease 192.168.1.145 for the Network Card with network address 001C26AC9D9E has been denied by the DHCP server 10.0.0.1 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
********************************************************************************
************************
GMER log
GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-29 06:16:50
Windows 5.1.2600 Service Pack 3, v.3264
Running: gmer.exe; Driver: C:\DOCUME~1\Bhaskara\LOCALS~1\Temp\awldiuob.sys
—- System - GMER 1.0.15 —-
SSDT 86292A78 ZwAlertResumeThread
SSDT 86290A78 ZwAlertThread
SSDT 85BB7828 ZwAllocateVirtualMemory
SSDT 86228A78 ZwConnectPort
SSDT 86207A78 ZwCreateMutant
SSDT 86291DB8 ZwCreateThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xAAC17350]
SSDT 86243CB8 ZwFreeVirtualMemory
SSDT 86201A78 ZwImpersonateAnonymousToken
SSDT 8623CA78 ZwImpersonateThread
SSDT 861FAD70 ZwMapViewOfSection
SSDT 8645F958 ZwOpenEvent
SSDT 8629FAC8 ZwOpenProcessToken
SSDT 86281AC8 ZwOpenThreadToken
SSDT 8625BFC0 ZwQueryValueKey
SSDT 86289AA0 ZwResumeThread
SSDT 86281A90 ZwSetContextThread
SSDT 86281CA0 ZwSetInformationProcess
SSDT 86280BF0 ZwSetInformationThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xAAC17580]
SSDT 8623AA78 ZwSuspendProcess
SSDT 8628AA78 ZwSuspendThread
SSDT 8628BE60 ZwTerminateProcess
SSDT 86280A78 ZwTerminateThread
SSDT 86217DC0 ZwUnmapViewOfSection
SSDT 86073A98 ZwWriteVirtualMemory
—- Devices - GMER 1.0.15 —-
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdePort0 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdePort1 [8654F6F2] atapi.sys[.reloc]
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [8654F6F2] atapi.sys[.reloc]
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\BTHUSB \Device\00000097 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
Device \Driver\BTHUSB \Device\00000099 bthport.sys (Bluetooth Bus Driver/Microsoft Corporation)
—- Processes - GMER 1.0.15 —-
Process C:\WINDOWS\system32\wuaclt.exe (*** hidden *** ) 3616
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001a6bc4394a
Reg HKLM\SYSTEM\ControlSet003\Services\BTHPORT\Parameters\Keys\001a6bc4394a (not active ControlSet)
—- EOF - GMER 1.0.15 —-