This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

RustockB and other little Goodies

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there all,

Im New to the forum but not to the spyware scene. i've cured many a PCs but this time im stuck. so i come to you guys for help. I hope to share my Anti-Spyware skills with everyone here and hopefully learn more about and how to fight Spyware. so if i ask any stupid questions like "why run this" or "what does this show" then please bear with me as i am also trying to learn ad understand it. with all that out of the way lets move on to the problem child.

Behind Door 1, is a New Dell Diminsion 9100 which is sick to it's stomache. I have scanned the carp** out of this thing and still havent been able to boot into normal mode. I can only boot to Safe mode. i also have a net connection but cant get out to the internet for some reason.

So far i have ran Adaware SE, Spy Sweeper, and am currently running Spybot. I have browsed this site and found a couple things but haven't tried them for fear of screwing up this PC. It's a Client of mine and needs to be finished ASAP.

Im willing to run whatever and log whatever just let me know what to do. I have GMER and other tools but i want a pro's advice before doing anything else. Thanks for all your help with this Problem.

Patrick Roye
Systems Engineer
===============
Attch:

Hijack This Log:

Logfile of HijackThis v1.99.1
Scan saved at 11:40:58 AM, on 2/7/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
\kasual02\apps\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrustITM\realmon.exe" -s
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DriveCleaner 2006 Free] "C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe" /min
O4 - HKLM\..\Run: [CBICompInstall] D:\Setup.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = C:\Program Files\Dell Wireless\PRISMCFG.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD3EB211-CCDB-45E3-A7A5-FC5550DDA5A5}: NameServer = 10.11.1.240,68.82.0.5,68.82.0.6
O20 - Winlogon Notify: ddcca - C:\WINDOWS\system32\ddcca.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: direct sound rss (dsrss) - Unknown owner - C:\WINDOWS\dsrss.exe (file missing)
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iTechnology iGateway 4.0 (iGateway) - Computer Associates International, Inc. - C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
O23 - Service: eTrust ITM RPC Service (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrustITM\InoRpc.exe
O23 - Service: eTrust ITM Realtime Service (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrustITM\InoRT.exe
O23 - Service: eTrust ITM Job Service (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrustITM\InoTask.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
I don't know what exactly is causing the boot issues, so we'll start with Rustock and see where that gets us.

When you run GMER, you should get a warning about a "system modification" - click Yes when given a choice
There should be an entry in red, something like C:\Windows\System32:huy32.sys. Yours may be slightly different depending on which version you have, but they should all be attached as Alternate Data Streams to the Windows\System32 folder - this is denoted by the colon between the folder and file names.
Right click the entry and select Delete the service. You will probably get an error message, but don't worry about it.

Next, run an ADS scan using HJT -

Run HJT and click on Open the Misc Tools section.
  • Click the Open ADS Spy… button.
  • Uncheck "Quick scan (Windows base folder only)"
  • Click the Scan button to the left of the Save log… button.
You should hopefully see an entry or two with the same name that GMER found. Check the box(es) next to these entries, and only these entries as some ADS are legit, and have HJT fix them.

Then give XP a chance to boot into Normal Mode and let me know how you've got on.
Thx for the reply Novicate, but i actually got it to boot into normal mode after various other scanners. i think Spybot was the kicker. lol. and i think the repair i also did helped alot. but i got it to boot into normal mode and right away spybot ran and found many other things. after that cam spy sweeper and NOC32, right now im running AntiSpywareSoftware or something like that. i forget the real name but i found it on this site. i would have followed your insctructions but you guys took way too long. as this was a clients PC i dont have time to wait for answers so for the record if i post here again (im sure i will, i like the way you guys do business!) that i cant wait for answers this long. ill wait 3 or 4 hrs but not too much longer. i also enrolled in the MRU, and hope to gain a better understanding of the way this stuff works. thanks for all your help, i hope to see you all again soon!

that i cant wait for answers this long. ill wait 3 or 4 hrs but not too much longer.

Are you charging your customers for the free service you're receiving at help sites? If you're looking for fixes within 3-4 hrs, when there are home users that have been waiting for our free services longer then a day or two, I suggest you seek help somewhere else. I would also suggest you donate to the creators of the free programs that are used to fix those pc's.

I'm glad you registered at MRU.

tashi
The malware removal forum is set up to help those in need of assistance with their personal computers. This service is free and provided by volunteers.

We realise on occasion a business where staff are trained to remove malware need a second opinion. In that case please state that up-front and note the steps already taken. Our volunteers appreciate that.

If the PC owner is being charged by you, please ensure it is a second opinion you are seeking, and not posting your jobs for others to clean.

Thank you for your understanding.

I apoligize if that came out rude, because after reading it again it does to me. I also did read the disclaimer but forgot about it while posting that reply. Thank you, LTD for clearing that up for me. I do agree that home users with personal computer should come first as they are not paying for the service. I was in the wrong by expecting fast service when other needed it most. I hope we see more of each other as i post my requests for second opinions and even when i've finished the MRU and help out here. as this was the place that got me started in all of it. Thanks for all you help, Novicate and LTD. until we meet again. Patrick Roye Systems Engineer

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI