JoeyRoland
Topic Starter
Hello to the now legendary staffers, (PC World Jan 2005). This is my first post here, so please be fragile
BACKGROUND:
So, here's my scenario: My friend got a "new" used computer and had me reformat it and reinstall everything. No problems. After I used the PC's included restore discs ect to setup his PC, I told him to download and install updates for WinXP. Of course, he didn't
Anyway, the other night, he and his fiancée were fighting over whether or not the female wrestler China was really a man or woman, (oh to be in love). His fiancée promptly googled stuff and came across some "interesting" websites - specifically about transvestites.
After his entire PC was overrun with Spyware, we ran Ad-Aware and Spybot: Search & Destroy. It found a lot of crap. However, it failed to do anything about it. Having some knowledge in this field, I had him download and run a logfile for Hijack This with version 1.99. He did and I had him remove several things. His PC is almost completely fine - except….
Before I had him disable "AutoComplete" in Internet Explorer, some of the more malicious websites were still visible in his address bar's drop-down list. For example, if he were typing in "google.com" after the letter "g", his address bar would show everything with that beginning. Specifically, a site addressed: gosex.com. All this despite wiping everything clean - manually!
Also, the other issue is a malicious file in his System32 folder in the Windows Directory. I am not too sure what the file is exactly, but even in safe mode, he cannot delete it.
So, after doing everything I can, I had him run another logfile. Below are the results. Please note, he isn't necessarily in "danger" of having his computer overrun again. That is, he seems to be able to do everything perfectly fine and after re-enabling IE's AutoComplete feature, he no longers even sees those aforementioned sights.
Any suggestions/help would be GREATLY appreciated!
SYMPTOMS: Home Page = ToonComics.com
iGuard Program running in background. Redirected web links. In ability to view/download popular anti-spy websites.
Specific: http://www.richardthelionhearted.com/~merijn/cwschronicles.html#tooncomics
LOG:
Logfile of HijackThis v1.99.0
Scan saved at 7:57:35 PM, on 2/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tony\Desktop\virus\HijackThis.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: winlogin.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE66EDBB-9F78-49ED-8ACF-31A6FA0B51AD}: NameServer = 204.255.212.14 206.66.216.8
O20 - AppInit_DLLs: r7vfr13284spupll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
*We thought we selected a disabled line O20…
Notes: He is using WindowsXP Professional Edition without any updates . Also, his Norton AntiVirus is worthless since his subscription has expired and hasn't been updated for ages. And lastly, for what it's worth, both he and his girl have different user accounts at the logon screen. I don't know if that matters, but I would rather not forget anything that could be important.
Again, any help is appreciated!
Thanks a bunch!
</Novel Over>
BACKGROUND:
So, here's my scenario: My friend got a "new" used computer and had me reformat it and reinstall everything. No problems. After I used the PC's included restore discs ect to setup his PC, I told him to download and install updates for WinXP. Of course, he didn't
Anyway, the other night, he and his fiancée were fighting over whether or not the female wrestler China was really a man or woman, (oh to be in love). His fiancée promptly googled stuff and came across some "interesting" websites - specifically about transvestites.
After his entire PC was overrun with Spyware, we ran Ad-Aware and Spybot: Search & Destroy. It found a lot of crap. However, it failed to do anything about it. Having some knowledge in this field, I had him download and run a logfile for Hijack This with version 1.99. He did and I had him remove several things. His PC is almost completely fine - except….
Before I had him disable "AutoComplete" in Internet Explorer, some of the more malicious websites were still visible in his address bar's drop-down list. For example, if he were typing in "google.com" after the letter "g", his address bar would show everything with that beginning. Specifically, a site addressed: gosex.com. All this despite wiping everything clean - manually!
Also, the other issue is a malicious file in his System32 folder in the Windows Directory. I am not too sure what the file is exactly, but even in safe mode, he cannot delete it.
So, after doing everything I can, I had him run another logfile. Below are the results. Please note, he isn't necessarily in "danger" of having his computer overrun again. That is, he seems to be able to do everything perfectly fine and after re-enabling IE's AutoComplete feature, he no longers even sees those aforementioned sights.
Any suggestions/help would be GREATLY appreciated!
SYMPTOMS: Home Page = ToonComics.com
iGuard Program running in background. Redirected web links. In ability to view/download popular anti-spy websites.
Specific: http://www.richardthelionhearted.com/~merijn/cwschronicles.html#tooncomics
LOG:
Logfile of HijackThis v1.99.0
Scan saved at 7:57:35 PM, on 2/13/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Acrobat 6.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Tony\Desktop\virus\HijackThis.exe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: winlogin.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O17 - HKLM\System\CCS\Services\Tcpip\..\{FE66EDBB-9F78-49ED-8ACF-31A6FA0B51AD}: NameServer = 204.255.212.14 206.66.216.8
O20 - AppInit_DLLs: r7vfr13284spupll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll.dll
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
*We thought we selected a disabled line O20…
Notes: He is using WindowsXP Professional Edition without any updates . Also, his Norton AntiVirus is worthless since his subscription has expired and hasn't been updated for ages. And lastly, for what it's worth, both he and his girl have different user accounts at the logon screen. I don't know if that matters, but I would rather not forget anything that could be important.
Again, any help is appreciated!
Thanks a bunch!
</Novel Over>