This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Serious worm infection

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please excuse my spelling, I have no spell checker and spelling was never my strongest english topic :blush: Hi, I've had my computer in a mess for about a week over this problem now. The basic symptom is internet traffic being redirected to 161816.com, or 121161.com, or other 6 digit varients. The only reason I noticed there was a problem was the fact that in doing this, it also downloaded more worms for me, which were caught by Avast AV. It is worth mentioning at this point that the only research I can find on this virus by googling, is another thread on this site (the only english site anyway, the rest are chinese.) Initially I backed everything up to an external HD, formatted the machines hard drive and reloaded my software, only to find "waiting for 161818.com" back in firefox's status bar. I assumed this was because I had infected my external and subsequently re-infected my machine. I am now using the PC with a freshly formatted HD, the only things that have been installed are Windows, Dell drivers, Firefox and now HijackThis v1.99.1. Needless to say it's still infected or I wouldn't be posting this here :P I'm at a total loss, a complete system wipe has always sorted me out in the past, I've never had a virus this persistant, in case it helps this is the HijackThis log; Logfile of HijackThis v1.99.1 Scan saved at 10:02:12, on 10/10/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\stsystra.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Hijackthis\HijackThis.exe O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe Any way you can help is much appreciated. * * Edit * * I have just installed and run Fixwareout, as advised in the self help section of the forum, here is the report from that program; Username "Rob" - 10/10/2007 10:36:02 [Fixwareout edited 9/01/2007] ~~~~~ Prerun check Successfully flushed the DNS Resolver Cache. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="" …. …. ~~~~~ Misc files. …. ~~~~~ Checking for older varients. …. ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "SigmatelSysTrayApp"="stsystra.exe" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] …. Hosts file was reset, If you use a custom hosts file please replace it… ~~~~~ End report ~~~~~
Hello and welcome to the forums

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.

Next:


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.


(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:

Download ComboFix from Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you, combofix.txt. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick while its running. That may cause it to stall
Hi, thank you for responding.

I have discovered something that the person with user name "sntlouisrams" on this forum may find interesting. I looked into some of the Chinese hits for 161816 using google's translate page function and found this; http://nielsliu.jiancss.com/archives/920049/ (that link should take you to the translated page) what I could make out from a less than perfect translation was that someone else with the same problem had found, that it was not his computer that was infected, but the gateway through which he connects. I have only experienced the problem while connecting through my university's intranet which made me wonder. I took my PC home today and thus far have not seen any evidence of traffic being redirected while using our standard broadband connection.

I will be taking my laptop back to my university halls some time before wednesday to test if the problem occurs using a machine that is certainly clean. I also have an appointment with a uni techie on wednesday and will post again to confirm if my suspicions are correct or not. In the mean time, it would be interesting to know whether or not "sntlouisrams" is connecting through a gateway?

* * EDIT * *

I have also just found this page (also from a Chinese site) ARP virus prevention which further supports my theory, it suggests that the virus targets routing tables.

I would advise user sntlouisrams to reset their router to it's "out of the box" configuration if possible. If indeed he or she is even connecting through a router at all. Hope it solves the mystery. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI