jimkoz
Topic Starter
Thanks in advance.
XP Pro, SP1
PC is currently disconnected from internet.
Most programs mentioned below ran in Safe Mode.
Originally had the lssas.exe, shutting down in 60 seconds error msg.
Ran Symantec's fix for sasser - it found nothing.
Symantec AV produces bogus MS Send Error message. (I believe the AV app has been altered)
CA's E-Trust AV online scan won't start in IE - IE closes, a bogus File Download windows pops up, only option is to download the page.
installation of AdAware, Spybot and Zone Alarm generates error message:
Ad-Aware SE: Ad-Aware.exe - Bad Image
The application or DLL C:\Windows\System32\ntshrui.dll is not a valid Windows image.
AdAware hangs when I run it.
Spybot only found Alexa.
Stinger finds nothing.
CPU at 100% (System process is hogging CPU cycles, System Idle Process at 0)
I have not cleaned out the temp directories yet as I'd like to ID this Virus or whatever it is.
PC hangs at shutdown
Currently running AVG to see if it finds something.
Edit: opening recycle bin gives this error msg:
The Recycle bin on C:\ is corrupted. Do you want to empty the Recycle Bin for this drive?
HiJack this log - in SAFE MODE! :
Logfile of HijackThis v1.99.0
Scan saved at 02:01:16 PM, on 01/07/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\TechSmith\SnagIt 6\SnagIt32.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mir.wustl.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {BD2A07D0-46EA-4CE5-8E5C-F67C7C1AC7F4} - C:\WINDOWS\System32\comctl3l2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://notesplace.wustl.edu/qp2.cab
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://medicor.wustl.edu/iNotes.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mir.wucon.wustl.edu
O17 - HKLM\Software\..\Telephony: DomainName = mir.wucon.wustl.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mir.wucon.wustl.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mir.wucon.wustl.edu
O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVNC.exe
XP Pro, SP1
PC is currently disconnected from internet.
Most programs mentioned below ran in Safe Mode.
Originally had the lssas.exe, shutting down in 60 seconds error msg.
Ran Symantec's fix for sasser - it found nothing.
Symantec AV produces bogus MS Send Error message. (I believe the AV app has been altered)
CA's E-Trust AV online scan won't start in IE - IE closes, a bogus File Download windows pops up, only option is to download the page.
installation of AdAware, Spybot and Zone Alarm generates error message:
Ad-Aware SE: Ad-Aware.exe - Bad Image
The application or DLL C:\Windows\System32\ntshrui.dll is not a valid Windows image.
AdAware hangs when I run it.
Spybot only found Alexa.
Stinger finds nothing.
CPU at 100% (System process is hogging CPU cycles, System Idle Process at 0)
I have not cleaned out the temp directories yet as I'd like to ID this Virus or whatever it is.
PC hangs at shutdown
Currently running AVG to see if it finds something.
Edit: opening recycle bin gives this error msg:
The Recycle bin on C:\ is corrupted. Do you want to empty the Recycle Bin for this drive?
HiJack this log - in SAFE MODE! :
Logfile of HijackThis v1.99.0
Scan saved at 02:01:16 PM, on 01/07/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\TechSmith\SnagIt 6\SnagIt32.exe
C:\Documents and Settings\Administrator\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mir.wustl.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {BD2A07D0-46EA-4CE5-8E5C-F67C7C1AC7F4} - C:\WINDOWS\System32\comctl3l2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://notesplace.wustl.edu/qp2.cab
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://medicor.wustl.edu/iNotes.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mir.wucon.wustl.edu
O17 - HKLM\Software\..\Telephony: DomainName = mir.wucon.wustl.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mir.wucon.wustl.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mir.wucon.wustl.edu
O23 - Service: pcAnywhere Host Service - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVRoam - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: VNC Server - RealVNC Ltd. - C:\Program Files\RealVNC\WinVNC\WinVNC.exe