Spyware / Malware / Virus Removal
[Resolved] Heap of Trouble :Win32.Backdoor.Agent & Others
18 min read
LDTate
Use add/remove programs and remove Teatimer or Spybot.
You can download it again after clean.
HGLD
LD,
I'm in bad shape again. Before I removed Spybot S&D I ran it then Adaware. Cleaned it. Rebooted. Spybot sent a registry change notice and asked for approval. I thought it was from the cleaning and OK'd it. Seconds later the email proliferation restarted.
Here's an adaware log, norton log and hijack log. I'm working off of my laptop again for obvious reasons.
What now?
ADWARE.BHO(GENERIC)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : clsid\{f10587e9-0e47-4cbe-84ae-7dd20b8684bb}
obj[1]=Regkey : interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836}
obj[2]=Regkey : typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb}
obj[3]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{f10587e9-0e47-4cbe-84ae-7dd20b8684bb}
obj[4]=Regkey : e404.e404mgr
obj[5]=Regkey : e404.e404mgr.1
Category: Security risks
Date Time,Feature,Risk Name,Result,Item Type,Virus Definition Version,Product Version,User Name,Computer Name,Details
1/1/2008 11:06:43 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 9:20:39 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 9:20:39 AM,Virus scanner,Backdoor.Trojan,Fully removed,File,2007.12.31.002,10.4.0.13,SYSTEM,HAROLD,"Source: [b138.exe] inside of [c:\documents and settings\hman\local settings\temporary internet files\content.ie5\mx9jhea5\8154ff2675af1b6e0677560871425153[1].zip],Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1199171985,Action taken: Fully removed"
1/1/2008 9:20:39 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 12:59:21 AM,Auto-Protect,Backdoor.Trojan,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\Documents and Settings\Hman\Local Settings\Temp\AAWTMP\C523312\200119\b138.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:41:01 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:58 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:55 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:06 AM,Auto-Protect,Downloader,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\ardCo17\ardCo172314.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:38:54 AM,Auto-Protect,Backdoor.Trojan,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\b138.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
12/29/2007 12:01:31 PM,Auto-Protect,Downloader,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\WINDOWS\mrofinu1000512.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947678,Action taken: Fully removed"
12/29/2007 12:01:29 PM,Auto-Protect,Downloader,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\WINDOWS\mrofinu1239.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947676,Action taken: Fully removed"
12/29/2007 12:01:28 PM,Auto-Protect,Infostealer,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\tsqfy.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947672,Action taken: Fully removed"
12/29/2007 12:01:28 PM,Auto-Protect,Infostealer,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\fych.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947637,Action taken: Fully removed"
12/25/2007 1:52:39 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/24/2007 5:02:40 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/24/2007 5:02:40 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 9:29:08 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 9:29:08 PM,Virus scanner,Adware.MaxSearch,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: [b122.exe] inside of [c:\documents and settings\hman\local settings\temporary internet files\content.ie5\akyb5d73\a8f5a020e4b833865a1034489887c8b9[1].zip],Risk category: Adware,Overall Risk Impact: Medium,Performance: 0,Privacy: 1198455014,Action taken: Fully removed"
12/23/2007 9:29:08 PM,Virus scanner,Downloader,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: [vmain.class] inside of [c:\documents and settings\hman\.jpi_cache\jar\1.0\jvmusafe.jar-6ba32b3d-6c67f728.zip],Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198454091,Action taken: Fully removed"
12/23/2007 9:29:08 PM,Virus scanner,Trojan.Gpcoder.E,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: ,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198453556,Action taken: Fully removed"
12/23/2007 9:28:07 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 6:28:22 PM,Auto-Protect,Adware.MaxSearch,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\b122.exe,Risk category: Adware,Overall Risk Impact: Medium,Performance: 0,Privacy: 1198452502,Action taken: Blocked"
12/23/2007 6:20:51 PM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\Documents and Settings\Hman\Local Settings\Temporary Internet Files\Content.IE5\AKYB5D73\installer[1].exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
12/23/2007 6:20:51 PM,Auto-Protect,Downloader,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\ardCo17\ardCo172314.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
11/10/2007 6:13:43 PM,Virus scanner,Adware.SystemProcess,Fully removed,File,2007.11.10.007,10.4.0.13,SYSTEM,HAROLD,"Source: ,Risk category: Adware,Overall Risk Impact: High,Performance: 0,Privacy: 1194736190,Action taken: Fully removed"
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:05 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://63.138.132.82/exchange
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://my.yahoo.com/p/d.html?v"); (C:\Documents and Settings\HMAN\Application Data\Mozilla\Profiles\default\5sih44uv.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_02.src"); (C:\Documents and Settings\HMAN\Application Data\Mozilla\Profiles\default\5sih44uv.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
O3 - Toolbar: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - C:\WINDOWS\System32\cachepal.exe
O9 - Extra 'Tools' menuitem: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - C:\WINDOWS\System32\cachepal.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted IP range: http://192.168.1.1
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143671063531
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
–
End of file - 8588 bytes
I'm in bad shape again. Before I removed Spybot S&D I ran it then Adaware. Cleaned it. Rebooted. Spybot sent a registry change notice and asked for approval. I thought it was from the cleaning and OK'd it. Seconds later the email proliferation restarted.
Here's an adaware log, norton log and hijack log. I'm working off of my laptop again for obvious reasons.
What now?
ADWARE.BHO(GENERIC)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : clsid\{f10587e9-0e47-4cbe-84ae-7dd20b8684bb}
obj[1]=Regkey : interface\{f7d09218-46d7-4d3d-9b7f-315204cd0836}
obj[2]=Regkey : typelib\{e63648f7-3933-440e-b4f6-a8584dd7b7eb}
obj[3]=Regkey : software\microsoft\windows\currentversion\explorer\browser helper objects\{f10587e9-0e47-4cbe-84ae-7dd20b8684bb}
obj[4]=Regkey : e404.e404mgr
obj[5]=Regkey : e404.e404mgr.1
Category: Security risks
Date Time,Feature,Risk Name,Result,Item Type,Virus Definition Version,Product Version,User Name,Computer Name,Details
1/1/2008 11:06:43 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 9:20:39 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 9:20:39 AM,Virus scanner,Backdoor.Trojan,Fully removed,File,2007.12.31.002,10.4.0.13,SYSTEM,HAROLD,"Source: [b138.exe] inside of [c:\documents and settings\hman\local settings\temporary internet files\content.ie5\mx9jhea5\8154ff2675af1b6e0677560871425153[1].zip],Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1199171985,Action taken: Fully removed"
1/1/2008 9:20:39 AM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
1/1/2008 12:59:21 AM,Auto-Protect,Backdoor.Trojan,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\Documents and Settings\Hman\Local Settings\Temp\AAWTMP\C523312\200119\b138.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:41:01 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:58 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:55 AM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\0.7887232.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:40:06 AM,Auto-Protect,Downloader,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\ardCo17\ardCo172314.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
1/1/2008 12:38:54 AM,Auto-Protect,Backdoor.Trojan,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\b138.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
12/29/2007 12:01:31 PM,Auto-Protect,Downloader,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\WINDOWS\mrofinu1000512.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947678,Action taken: Fully removed"
12/29/2007 12:01:29 PM,Auto-Protect,Downloader,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\WINDOWS\mrofinu1239.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947676,Action taken: Fully removed"
12/29/2007 12:01:28 PM,Auto-Protect,Infostealer,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\tsqfy.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947672,Action taken: Fully removed"
12/29/2007 12:01:28 PM,Auto-Protect,Infostealer,Fully removed,File,2007.12.28.003,10.4.0.13,SYSTEM,HAROLD,"Source: C:\qoobox\Quarantine\C\fych.exe.vir,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198947637,Action taken: Fully removed"
12/25/2007 1:52:39 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/24/2007 5:02:40 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/24/2007 5:02:40 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 9:29:08 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 9:29:08 PM,Virus scanner,Adware.MaxSearch,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: [b122.exe] inside of [c:\documents and settings\hman\local settings\temporary internet files\content.ie5\akyb5d73\a8f5a020e4b833865a1034489887c8b9[1].zip],Risk category: Adware,Overall Risk Impact: Medium,Performance: 0,Privacy: 1198455014,Action taken: Fully removed"
12/23/2007 9:29:08 PM,Virus scanner,Downloader,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: [vmain.class] inside of [c:\documents and settings\hman\.jpi_cache\jar\1.0\jvmusafe.jar-6ba32b3d-6c67f728.zip],Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198454091,Action taken: Fully removed"
12/23/2007 9:29:08 PM,Virus scanner,Trojan.Gpcoder.E,Fully removed,File,2007.12.23.002,10.4.0.13,SYSTEM,HAROLD,"Source: ,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Privacy: 1198453556,Action taken: Fully removed"
12/23/2007 9:28:07 PM,Virus scanner,,Backup only,File,,10.4.0.13,SYSTEM,HAROLD,"Source: c:\WINDOWS\SYSTEM32\xpdx.sys,Action taken: Backup only"
12/23/2007 6:28:22 PM,Auto-Protect,Adware.MaxSearch,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\b122.exe,Risk category: Adware,Overall Risk Impact: Medium,Performance: 0,Privacy: 1198452502,Action taken: Blocked"
12/23/2007 6:20:51 PM,Auto-Protect,Trojan.Dropper,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\Documents and Settings\Hman\Local Settings\Temporary Internet Files\Content.IE5\AKYB5D73\installer[1].exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
12/23/2007 6:20:51 PM,Auto-Protect,Downloader,Blocked,File,N/A,10.4.0.13,SYSTEM,HAROLD,"Source: C:\WINDOWS\SYSTEM32\ardCo17\ardCo172314.exe,Risk category: Virus,Overall Risk Impact: High,Performance: 1,Action taken: Blocked"
11/10/2007 6:13:43 PM,Virus scanner,Adware.SystemProcess,Fully removed,File,2007.11.10.007,10.4.0.13,SYSTEM,HAROLD,"Source: ,Risk category: Adware,Overall Risk Impact: High,Performance: 0,Privacy: 1194736190,Action taken: Fully removed"
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:45:05 PM, on 1/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\SiteAdvisor\6253\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Verizon\McciTrayApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://63.138.132.82/exchange
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://my.yahoo.com/p/d.html?v"); (C:\Documents and Settings\HMAN\Application Data\Mozilla\Profiles\default\5sih44uv.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_02.src"); (C:\Documents and Settings\HMAN\Application Data\Mozilla\Profiles\default\5sih44uv.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\NppBho.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
O3 - Toolbar: MySpace Customizer Toolbar - {423a0a67-20c5-4b79-a4b7-2456e79acf5a} - C:\Program Files\MySpace_Customizer\tbMyS1.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.7\UIBHO.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6253\SiteAdv.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Verizon_McciTrayApp] C:\Program Files\Verizon\McciTrayApp.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\PROGRAM FILES\QUICKTIME\QTTASK.EXE" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - C:\WINDOWS\System32\cachepal.exe
O9 - Extra 'Tools' menuitem: CachePal - {5F4A4622-8370-440e-88CC-CA2256D1A08A} - C:\WINDOWS\System32\cachepal.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted IP range: http://192.168.1.1
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommo…IOS/tgctlcm.cab
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/…nSSWebAgent.CAB
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1143671063531
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
–
End of file - 8588 bytes
LDTate
* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
- Doubleclick the drweb-cureit.exe file and Allow to run the express scan
- This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
- Once the short scan has finished, mark the drives that you want to scan.
- Select all drives. A red dot shows which drives have been chosen.
- Click the green arrow at the right, and the scan will start.
- Click 'Yes to all' if it asks if you want to cure/move the file.
- When the scan has finished, look if you can click next icon next to the files found: [external image: Posted Image]
- If so, click it and then click the next icon right below and select Move incurable as you'll see in next image:
[external image: Posted Image]
This will move it to the %userprofile%\DoctorWeb\quarantaine-folder if it can't be cured. (this in case if we need samples) - After selecting, in the Dr.Web CureIt menu on top, click file and choose save report list
- Save the report to your desktop. The report will be called DrWeb.csv
- Close Dr.Web Cureit.
- Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
- After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
HGLD
I'm back at work so I won't be home to do this until around 6PM tonight. Does it matter if I download Dr. Web to a flash drive and put it on my PC or do I need to do the download from the PC?
LDTate
Shouldn't matter.I'm back at work so I won't be home to do this until around 6PM tonight. Does it matter if I download Dr. Web to a flash drive and put it on my PC or do I need to do the download from the PC?
HGLD
I'm running Dr. Web right now. It id'd smitRem which is a removal tool that I used before. Do yo know it?
http://noahdfear.geekstogo.com/
It's in a folder on my desktop.
It then found Virtumod.240 in is68603.exe in a Temporary Internet File (maybe it reloads on startup because I used ATF earlier and haven't been online on that pc since).
It asked me about curing is68603.exe and I chose "yes to all".
It's about 25% through the scan. The express scan found nada.
http://noahdfear.geekstogo.com/
It's in a folder on my desktop.
It then found Virtumod.240 in is68603.exe in a Temporary Internet File (maybe it reloads on startup because I used ATF earlier and haven't been online on that pc since).
It asked me about curing is68603.exe and I chose "yes to all".
It's about 25% through the scan. The express scan found nada.
LDTate
smitRem is a legit program, but you don't have a smitfraud infection so you should delete it.
HGLD
Why do you think Dr. Web flagged it?
LDTate
Is the scan done?Why do you think Dr. Web flagged it?
Let it clean ( cure ) whatever it finds.
If you clean out your temp files before shutting down those will be gone, but you shouldn't be getting .exe, .com, .bat files added even to your temp files unless you were downloading something. What were you doing during that time the file was downloaded to the temp files?
HGLD
Are you referring to is68603.exe? I wasn't downloading anything, at least knowingly. I must have hit a page that executed a script.
I'm only 73% scanned. It has also found a .reg Trojan.StartPage and 3 Downloaders.
LDTate
Good. Let it do it's jobAre you referring to is68603.exe? I wasn't downloading anything, at least knowingly. I must have hit a page that executed a script.
I'm only 73% scanned. It has also found a .reg Trojan.StartPage and 3 Downloaders.
HGLD
5% to go.
HGLD
reboting now.
HGLD
Windows can not open DrWeb.csv.
LDTate
Try right Clicking on it and select Open With and select notepadWindows can not open DrWeb.csv.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI