Assorted weirdness going on. IE Browser hijacked to "sysprotect.com", software installing itself (Cowbanga by oin), shortcuts appearing on desktop (green and yellow shields resemblinging Windows Update, but advising that computer is infected, lots of popups trying to have me by anti-spyware software…etc.)
Have done the following:
1. Updated and ran NAV: Detected two viruses "Trojan.Zlob" and "Trojan.Nebuler". Could not repair, access to file denied. File was: C:\Windows\system32\winrvc32.dll
2. Updated and Ran SpyBot. Detected "Zlob.downloader". Attempted repair. Could not repair two files beloning to Zlob: C:\Windows\system32\stdole3.tlb and C:\Windows\system32\\afmclk.exe
3. Updated and Ran Adaware SE. Detected "Trojan.small". Attempted repair. Again could not repair two files named: C:\Windows\system32\dcomcfg.exe and C:\Windows\system32\stdole3.tbl (again).
4. Downloaded, updated and ran EWIDO in safe mode. Detected 28 things. Repaired them all. Saved log (below)
5. Reboot
6. Was able to reset homepage on IE.
7. Re-Ran Spybot and Adaware…still detecting "Zlob" and not able to repair +C:\Windows\system32\stdole3.tbl
8. Ran HJT (Renamed to AnalyzeMe as advised on this forum). Log attached below.
Any help greatly appreciated.
Mr. B.
HJT Log
———-
Logfile of HijackThis v1.99.1
Scan saved at 3:51:58 PM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Common Files\{E8A7665F-0963-1033-0209-040311190001}\Update.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Navnt\navapw32.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Navnt\navapsvc.exe
C:\PROGRA~1\Navnt\npssvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\Navnt\alertsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\John\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://antwrp.gsfc.nasa.gov/apod/astropix.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…B_PVER}&ar;=home
O4 - HKLM\..\Run: [NPS Event Checker] C:\PROGRA~1\Navnt\npscheck.exe
O4 - HKLM\..\Run: [NAV DefAlert] C:\PROGRA~1\Navnt\defalert.exe
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [Omnipage] D:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
O4 - Global Startup: Norton AntiVirus AutoProtect.lnk = C:\Program Files\Navnt\navapw32.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NAV Alert - Symantec Corporation - C:\PROGRA~1\Navnt\alertsvc.exe
O23 - Service: NAV Auto-Protect - Symantec Corporation - C:\PROGRA~1\Navnt\navapsvc.exe
O23 - Service: Norton Program Scheduler - Symantec Corporation - C:\PROGRA~1\Navnt\npssvc.exe
Ewido Log
———–
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 3:44:36 PM 7/8/2006
+ Scan result:
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\UYX8ZF9W\YazzleActiveX[1].cab/YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined).
C:\WINDOWS\system32\taskmgr.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\UYX8ZF9W\anti4[1].exe -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cbxyxvt.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
D:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-18038922-6af18ed8.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Ignored.
C:\WINDOWS\system32\zlara.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Ignored.
:mozilla.54:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.123:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.125:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.29:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.31:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.19:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.49:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.50:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.51:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.52:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.20:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.16:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.17:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.10:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\f07ajj8p.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.81:D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\pjhnjhvp.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
C:\WINDOWS\system32\winrvc32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\Documents and Settings\John\Local Settings\Temporary Internet Files\Content.IE5\R25A5NYS\!update-4020[1].0000 -> Trojan.PurityAd : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\!update.exe -> Trojan.PurityAd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\1024\ldE030.tmp -> Trojan.Small : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined).
::Report end