Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

2nd PC now affected with Malware [RESOLVED]


  • This topic is locked This topic is locked

#1
BlackVinyl

BlackVinyl

    Member

  • Member
  • PipPip
  • 46 posts
Hi,
If someone could help with this issue as well, it would be greatly appreciated.
This is the 2nd PC which I use for work and it has been infected with a similar virus/trojan to the first PC.

However, on the off chance it's a different type of infection, below is the HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 5:34:12 PM, on 7/07/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Antivirus Files\hjt\HJT_and_more_1\HJT and more 1\HijackThis.exe

O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

SOMEONE'S IMMEDIATE ATTENTION WOULD BE GREATLY APPRECIATED! :tazz:

Thank you.

BV ;)
  • 0

Advertisements


#2
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi BlackVinyl

Please read through the instructions before you start (you may want to print this out).

Please set your system to show all files; please see here if you're unsure how to do this.

Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first. Don't run yet.

Download Pocket Killbox and unzip it; save it to your Desktop. We may need it later.

Please download SpyBot V1.4 http://www.majorgeek...wnload2471.html Update the program then run it.

Download Ewido Trojan’s and malware remover http://www.ewido.net/en/download/
This setup contains the free as well as the plus-version of the ewido security suite. After the installation, a free 14-day test version containing all the extensions of the plus-version will be activated. At the end of the test phase, the extensions of the plus version are deactivated and the freeware version can be used unlimited times. The purchased license code of the plus version can be entered at any time.
Ewido will auto-udate. Don't run yet

Reboot into Safe Mode: please see here if you are not sure how to do this.

Run Ewido full scan. Save the scan.log.

Run Ad-aware se let remove all it finds

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:

Please download, install and run this disk cleanup utility called Cleanup version 4.0!: http://downloads.ste...p/CleanUp40.exe
It will get rid of any malware which may be hiding in your temp folders ( a common hiding place). You will also regain a massive amount of disk space. Here is a tutorial which describes its usage: http://www.bleepingc...tutorial93.html
Check the custom settings to your liking under options, but be sure to delete temporary files and temporary internet files for all user profiles. Also, cleanout the prefetch folder and the recycle bin.When the scan has finnished click the close button
When prompted the system will log off to let it clean out the remaining files. when the log screen shows log back on and continue the fix.

Please download spyware-scan and save it to your desktop.
Please post the logs From Ewido and HijackThis We will need them to remove previous infections that have left files on your system.

Kc :tazz:
  • 0

#3
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Hi thatman,
Thanks for your response.

OK, now going through your instructions, here are the answers...

- System showing all files
- Ad-Aware installed and updated but not executed yet
- Killbox already on my desktop (read other forum topics and dl just in case) :tazz:
- Spybot 1.4 already installed, updated and running
- IE could not open the page for Ewido so I did a search and dl from here... http://www.download....4-10326287.html
However, after installing, I cannot update it. Nothing happens when I click on online update.

The remaining steps I did not do because I want to do them in the order you specified. Although, I dl Spyware Scan onto my desktop.

How can I get Ewido to update so I can scan in safe mode and provide the log for you?

Thanks,

BV ;)
  • 0

#4
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi BlackVinyl

Make sure your firewall is not blocking ewido.

When you first install ewido it normally auto-update's

Kc :tazz:
  • 0

#5
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Hi again,

I don't have a firewall!
Should I perhaps re-boot after installing because it didn't prompt me to re-boot?

Thanks,
BV
  • 0

#6
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Howdy,
OK, I got Ewido to update and scan, however, I could not do it Safe Mode because I have a serial mouse (not PS2) and my mouse was not operational in safe mode. I tried to use the keyboard (TAB keys etc) but could not get it to run a scan, so I did it after a normal re-boot.

Here are the requested logs...

Logfile of HijackThis v1.99.1
Scan saved at 5:13:34 PM, on 11/07/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\AcroDist.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Intuit\QuickBooks\qbw32.exe
C:\Antivirus Files\hjt\HJT_and_more_1\HJT and more 1\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O15 - Trusted Zone: http://www.emailcash.com.au
O15 - Trusted Zone: http://www.ewido.net
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

AND...

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 1:46:33 PM, 11/07/2005
+ Report-Checksum: DB5B4873

+ Scan result:

HKLM\SOFTWARE\Classes\Interface\{1E1B2878-88FF-11D2-8D96-D7ACAC95951F} -> Spyware.CommonName : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{1E1B286C-88FF-11D2-8D96-D7ACAC95951F} -> Spyware.CommonName : Cleaned with backup
C:\Antivirus Files\hjt\HJT_and_more_1\HJT and more 1\backups\backup-20050707-153913-752.dll -> Trojan.Puper.m : Cleaned with backup
C:\Antivirus Files\hjt\HJT_and_more_1\HJT and more 1\backups\backup-20050707-155231-110.dll -> Trojan.Puper.m : Cleaned with backup
C:\Antivirus Files\hjt\HJT_and_more_1\HJT and more 1\backups\backup-20050707-171633-571.dll -> Trojan.Puper.m : Cleaned with backup


::Report End

From what you requested, the only thing I could not do was delete the 'pre-fetch' folder from within the options of CleanUp. That particular option was greyed out.

What next?

Thanks

BV
  • 0

#7
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi BlackVinyl

Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
Please post the logs From Panda, HJT.logWe will need them to remove previous infections that have left files on your system.

Kc :tazz:
  • 0

#8
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Hi,
I cannot post the Active Scan log because it found no viruses, thus not giving me the option to save anything.

What next?

Thanks,

BV
  • 0

#9
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Oops! Sorry I forgot to add the latest HJT log.

Here you go...

Logfile of HijackThis v1.99.1
Scan saved at 10:51:29 AM, on 12/07/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Microsoft Office\Office\1033\msoffice.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Antivirus Files\hjt\HJT_and_more_1\HJT and more 1\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O15 - Trusted Zone: http://www.emailcash.com.au
O15 - Trusted Zone: http://www.ewido.net
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe

OK, so what next?

Cheers,

BV
  • 0

#10
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi BlackVinyl

Congratulations! Your system is CLEAN ;)

Microsoft® Windows AntiSpyware (Beta) 2000 and XP ONLY.
Please download SpyBot V1.4 http://www.majorgeek...wnload2471.html
Spybot Tutorial
Disable Spybot Tutorial

Winpatrol Free

Ad-Aware SE Personal Edition Free
AdAware Tutorial

Turn of system restore
Disabling or enabling Windows XP System Restore
WIndows ME
Defrag your hard drive. Turn system restore back on and create a new restore point.

Tony Klien: So how did I get infected in the first place

How do you prevent spyware from being installed again? We strongly recommend installing SpywareBlaster (it's free for personal use). Click Here
QUOTE
Prevent the installation of ActiveX-based spyware, adware, browser hijackers, dialers, and other potentially unwanted pests.
Block spyware/tracking cookies in Internet Explorer and Mozilla/Firefox.
Restrict the actions of potentially dangerous sites in Internet Explorer.
Consumes no system resources.

Download, run, check for updates, download updates, select all, protect against checked. All done. Check for updates every couple of weeks. If you have any errors running the program like a missing file see the link at the bottom of the javacool page.

It's also very important to keep your system up to date to avoid unnecessary security risks. Click Here to make sure that you have the latest patches for Windows.

These next two steps are optional, but will provide the greatest protection.
1. Use ANY browser besides Internet Explorer, almost every exploit is crafted to take advantage of an IE weakness. We usually recommend FireFox.
http://www.mozilla.o...oducts/firefox/
2. Install Sun's Java. It's much more secure than Microsoft's Java Virtual Machine .
You can download Sun's newer JVM for Windows at http://java.sun.com/getjava/index.html.
http://www.java.com/...load/manual.jsp Windows (Offline Installation)

After doing all these, your system will be thoroughly protected from future threats.

Have a nice Day.

Kc :tazz:
  • 0

#11
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Thanks thatman! :tazz:

I will try to follow all the steps you listed in the final post, however, I already have Spybot 1.4 so I will skip that one.

The only 2 things I would like to ask is...
1. Can I now delete all the files you asked me to DL to my desktop and run (eg. Killbox, TMAS web scanner, HJT etc etc), also, is Ewido still necessary to have installed?

2. My PC may be fine with regards to spyware/trojans, but it seems to be running very sluggish at the moment. Any idea why? My guess is that some of these programs which I installed may be a little resource hungry. I think that it may be because of Ewido, Spybot, Spysweeper Ad Aware SE etc. Am I right or is it something else?

Thanks heaps for all your assistance.

BV ;)
  • 0

#12
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi BlackVinyl

You can delete the DL programs

Uninstall ewido
Uninstall program you don't use.

I would keep HJT is is a handy program to use have a good look at the options it has.
With your system now clean scan with HJT and save the log clean.log then you can check if any items have been add that you did not Download.

Kc :tazz:
  • 0

#13
BlackVinyl

BlackVinyl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 46 posts
Thank you thatman,

All your assistance is much appreciated.

Have a great day!

BV
  • 0

#14
Guest_thatman_*

Guest_thatman_*
  • Guest
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP