Network Problems And Extra Volume
Hello,
I've come down with a nasty piece of malware. Running WinXP Home, SP2 on a greybox, legal version of the OS.
A couple of days ago BD found and quarantined a virus. I sent it & deleted, and don't remember what it was. But next time I booted, the machine began steady low level network traffic, up and down. I blocked the network, unplugged the ethernet cable, and started looking around:
Task manager was showing several instances of svchost.exe, also alg.exe which was not visible before.
Task manager was showing instances of local service and network service along with system and my login.
Network settings control panel was showing a new network connection, named application layer gateway. I could disable this, which killed my network connection, but could not delete it. Prior network connection was still visible and when I disabled it, that also killed the network connection.
Unable to create a new network connection.
Also, on my old boot drive (with a damaged version of WinXP home) I found a 16GB volume that I certainly didn't put there. Running apps of Ultimate Boot Disk showed "unknown" for disk type (rest of the drive, like the others, is NTFS).
Ran a complete system scan with BD and it quarantined trojan.generic-165605. Also ran full scans with Windows Defender, Ad-aware, and Spybot, and they showed nothing unusual.
But since then, the new network connection is no longer visible. And in normal windows mode, the original network icon shows that it is enabled and connected. However the network is not functioning and I cannot send a ping.
If I reboot into safe mode with networking, the network is operational and seems to behave itself; at least, I'm not seeing any excessive activity on the switch my machine is connected to.
I haven't tried anything irreversible (e.g., wipe that drive with the weird volume) or windows repair. But here is my HiJack This file (windows normal mode):
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:23:50 PM, on 5/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Windows Defender\MsMpEng.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\Program Files\FarStone\RestoreIT\RestoreIT_XP\VBPTASK.EXE
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Intel\IDU\iptray.exe
E:\Program Files\SiteAdvisor\6261\SiteAdv.exe
E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
E:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
E:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe
E:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
E:\Program Files\Microsoft IntelliPoint\ipoint.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
E:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
E:\Program Files\Windows Defender\MSASCui.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
E:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
E:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Intel\IDU\awServ.exe
E:\Program Files\Bonjour\mDNSResponder.exe
E:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
E:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
E:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
E:\WINDOWS\system32\nvsvc32.exe
E:\Program Files\SiteAdvisor\6261\SAService.exe
E:\WINDOWS\system32\svchost.exe
E:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
E:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
E:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
E:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\wuauclt.exe
\Upgrades\highjackthis\HiJackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - E:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - E:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - E:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [intelAudioStudio] "E:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" BOOT
O4 - HKLM\..\Run: [DiskeeperSystray] "E:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [RestoreIT!] "E:\Program Files\FarStone\RestoreIT\RestoreIT_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ipTray.exe] "E:\Program Files\Intel\IDU\iptray.exe"
O4 - HKLM\..\Run: [siteAdvisor] "E:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "E:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [bDAgent] "E:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [XboxStat] "e:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [intelliPoint] "E:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] E:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe
O4 - HKLM\..\Run: [mxomssmenu] "E:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [Windows Defender] "E:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [spybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: NaturalColorLoad.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1203385224984
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu...b?1203385217703
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - E:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - E:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Admin Works Agent X8 (AWService) - OSA Technologies Inc., An Avocent Company - E:\Program Files\Intel\IDU\awServ.exe
O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Diskeeper - Diskeeper® Corporation - E:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: iPod Service - Apple Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - E:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: MaxBackServiceInt - Unknown owner - E:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: MaxSyncService (NTService1) - - E:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PinnacleUpdate Service (PinnacleUpdateSvc) - KALiNKOsoft - E:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe
O23 - Service: SiteAdvisor Service - Unknown owner - E:\Program Files\SiteAdvisor\6261\SAService.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - E:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - E:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - E:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe
--
End of file - 8539 bytes
Thanks in advance for any help you can give me on this one!
jfs
Comments
-
The log is clean !
0 -
The log is clean !
Hmm, thanks! Guess I will work to fix the windows network problem...and the weird disk volume. Appreciate your looking at my data!
jfs0 -
What version of BD do you have ?! (9/10/11 ?!)
Antivirus or Internet Security ?!
Please try to run a complete scan with SUPERAntiSpyware (ad-aware && Windows Defender don't do the job)0 -
Hello jfs_1950,
If you are using BitDefender Total Security 2008 (this is version 11) or BitDefender Internet Security 2008 navigate to the firewall section and more specificly to the zones section. Do you see any untrusted network? If so double click on it and change it to trusted. After that go to the traffic tab and press on reset profile. Reboot your pc.
If that fails try this first right click on your network connection and click on repair. Reboot your pc afterwards see if you still have the problem in normal mode. If that is the case please download winsockfix from here. Download it and press on fix and reboot your pc afterwards. Try also this unplug the main powercable of your router for 30 seconds and plug it back in.
Best regards
Niels0 -
What version of BD do you have ?! (9/10/11 ?!)
Antivirus or Internet Security ?!
Please try to run a complete scan with SUPERAntiSpyware (ad-aware && Windows Defender don't do the job)
Well, the malware won't let me install SUPERAntiSpyware. If I try it says the administrator has set policies to prevent it. And when I go into properties and try to reset the security settings, it will not let me. The "OK" button is greyed out. Attempting to do it in safe mode. Logging in as administrator or myself makes no difference. I guess it's afraid of this app so once I get this under control I guess I'll buy the full version! I never heard of this tool before, thanks for pointing me to it!
Regarding BitDefender I am running Internet Security 2008.0 -
0
-
Okay, I tried Malwarebytes' Anti-Malware. Installed properly over the internet. Deep scan came up clean.
I still cannot install Superantispyware. I have tried the registry fixes I found on the web that supposedly address the "The system administrator has set policies to prevent this installation" error. Regedit showed normal indication for HKLM\software\policies\microsoft\windows\installer. And there is no visible registry entry for superantispyware at HKEY_CLASSES_ROOT\installer\products, so there's nothing to delete.
Tried to re-register the windows installer, no effect. Haven't tried reinstalling it yet. Hoping you can give me some advice on how to get my installer back so I can run superantispyware.
Network remains down in normal mode, but works in safe mode with networking, and with no abnormal indications on the external switch. I have not tried to fix it as you all advised, still hoping to verify whether or not the malware is dead.
And thanks for the help.0 -
Hello jfs_1950,
Can you please download combofix you will find it here. Print the following instructions and read them carefully. Please post the output of the scan into your next post. So I or someone else can see if there is still some infections.
To change your rights please open the registry editor by pressing the windows button together with r now typ regedit press enter. Now right click on HKEY_LOCAL_MACHINE choose premissions see if your user account is allowed to have full access and has read access. If not check the boxes and press on apply and ok. You have to do this also for the 4 remaining folders. Reboot your pc and see if superantispyware can install now.
Best regards
Niels0 -
I can't tell you how much I appreciate your help.
Okay, the easy part first. I looked at my permissions in the registry and indeed, in one case (HKLM) I had limited rights. I fixed that and also found an "unknown user" and I deleted its rights.
Ran combofix in safe mode. Maybe that was a mistake and I should have done it in normal mode. If so sorry, the instructions didn't say which mode to run. But after that when I booted into normal mode I found two problems: (1) desktop now shows only wallpaper, no icons or taskbar. (2) Was seeing a lot of network traffic again. This could have been BitDefender doing an upgrade, because it has been disconnected for nearly a week, but I had no way of knowing so I yanked the cable and restarted into safe mode with networking.
Machine now takes quite a bit longer to load into normal mode than before.
Safe mode with networking seems to work ok. I still cannot install superantispyware, the same error (system administrator has set policies to prevent this installation) still comes up. The malware must really hate that program.
Here is the combofix log:
ComboFix 08-06-04.1 - Julius 2008-06-04 18:20:43.1 - NTFSx86 NETWORK
Running from: E:\Documents and Settings\Julius\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-03 17:30 . 2008-06-03 17:30 <DIR> d-------- E:\Program Files\Malwarebytes' Anti-Malware
2008-06-03 17:30 . 2008-06-03 17:30 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-03 17:30 . 2008-06-03 17:30 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-03 17:30 . 2008-05-30 01:06 34,296 --a------ E:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-03 17:30 . 2008-05-30 01:06 15,864 --a------ E:\WINDOWS\system32\drivers\mbam.sys
2008-06-03 06:27 . 2008-06-03 06:27 <DIR> d---s---- E:\Documents and Settings\Administrator\UserData
2008-05-30 20:49 . 2008-05-30 20:49 <DIR> d-------- E:\Program Files\Spybot - Search & Destroy
2008-05-30 20:49 . 2008-05-30 21:11 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-30 20:26 . 2008-05-30 20:26 <DIR> d-------- E:\Program Files\Windows Defender
2008-05-29 20:16 . 2008-05-29 20:16 <DIR> d-------- E:\Program Files\Lavasoft
2008-05-29 20:16 . 2008-05-29 20:17 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-29 20:10 . 2008-06-02 19:20 <DIR> d-------- E:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 12:42 . 2008-05-26 12:42 <DIR> d--hs---- E:\WINDOWS\ftpcache
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ E:\WINDOWS\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 23:57 --------- d-----w E:\Program Files\Mozilla Thunderbird
2008-05-28 00:00 --------- d-----w E:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-25 13:03 --------- d-----w E:\Program Files\Java
2008-05-24 18:51 --------- d-----w E:\Program Files\SiteAdvisor
2008-05-10 16:38 --------- d-----w E:\Documents and Settings\Julius\Application Data\SiteAdvisor
2008-05-03 19:28 --------- d-----w E:\Documents and Settings\All Users\Application Data\Maxtor
2008-05-03 19:26 --------- d-----w E:\Program Files\Maxtor
2008-05-03 19:25 --------- d--h--w E:\Program Files\InstallShield Installation Information
2008-04-29 15:20 15,648 ----a-w E:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w E:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w E:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-12 19:55 --------- d-----w E:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-11 00:02 --------- d-----w E:\Program Files\NetWaiting
2008-04-10 23:47 --------- d-----w E:\Program Files\Hayes
2008-04-05 21:03 --------- d-----w E:\Program Files\QuickTime
2008-04-05 21:01 --------- d-----w E:\Program Files\iTunes
2008-04-05 21:01 --------- d-----w E:\Program Files\iPod
2008-04-05 20:56 --------- d-----w E:\Documents and Settings\Julius\Application Data\Apple Computer
2008-03-27 08:12 151,583 ----a-w E:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w E:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="sttray.exe" []
"IntelAudioStudio"="E:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2006-08-02 18:17 9134080]
"DiskeeperSystray"="E:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-02-24 20:29 196709]
"farstone"="" []
"RestoreIT!"="E:\Program Files\FarStone\RestoreIT\RestoreIT_XP\VBPTASK.exe" [2005-04-30 01:09 122880]
"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [2007-05-11 07:03 8429568]
"nwiz"="nwiz.exe" [2007-05-11 07:03 1626112 E:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="E:\WINDOWS\system32\NvMcTray.dll" [2007-05-11 07:03 81920]
"ipTray.exe"="E:\Program Files\Intel\IDU\iptray.exe" [2006-11-24 13:26 2209792]
"SiteAdvisor"="E:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-12-04 17:03 36640]
"Adobe Reader Speed Launcher"="E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"BitDefender Antiphishing Helper"="E:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 16:46 61440]
"BDAgent"="E:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-22 19:33 360448]
"XboxStat"="e:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 19:05 734264]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"IntelliPoint"="E:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 21:09 842584]
"QuickTime Task"="E:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="E:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"MaxtorOneTouch"="E:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-27 15:04 712704]
"mxomssmenu"="E:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 16:24 81920]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NaturalColorLoad.lnk - E:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2008-02-23 15:20:53 155715]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= E:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"E:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe /autorun
\Shell\directx\command - G:\DirectX\dxsetup.exe
\Shell\setup\command - G:\setup.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-04 22:11:56 E:\WINDOWS\Tasks\MP Scheduled Scan.job"
- E:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-04 18:21:58
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: E:\WINDOWS\system32\winlogon.exe
-> E:\WINDOWS\system32\tsd32.dll
.
Completion time: 2008-06-04 18:22:32
ComboFix-quarantined-files.txt 2008-06-04 22:22:26
Pre-Run: 238,846,861,312 bytes free
Post-Run: 239,082,455,040 bytes free
114 --- E O F --- 2008-05-15 18:51:110 -
Addendum after I thought about this. It is possible that my desktop problem came from running combofix in safe mode. Because when it cleared the desktop, the safe mode alert about running in safe mode came up. Usually you have to hit okay at that point and then windows loads the desktop. But the combofix instructions state you shouldn't do anything while combofix is doing its thing, so I didn't hit okay. And the desktop was black at the end, no icons, until I restarted.
Seems to me there might be an ambiguity in the combofix instructions. Not your fault, obviously.
So now, I have desktop icons or taskbar when in safe mode, but no icons or taskbar in normal mode. And I am not sure if this is due to the malware or due to combofix behavior when run in safe mode.
If you can help me get the icons and taskbar back in normal mode, I can run combofix again in normal mode and we can see if there are differences.
Thanks for the help!0 -
Hello jfs_1950,
Please try this press the following keys together: ctrl+alt+del (control,alt and delete button) Go to the file menu and choose new task and type explorer.exe and press enter. If that fails reboot your pc into safe mode but select load lastworking configuration. So far I can't find any suspecious entries in your combofix log.Comboxfix should automatically reboot your pc.
Best regards
Niels0 -
Thank you Niels and Crysty2k5!
I will try that tonight. I do have control of the task mgr window.
I'm slowly chipping away at the malware's defenses that keep me from installing superantispyware. After I found the extra user in the registry (named S-1-5-21- with a long string of numbers following), I deleted that in the registry and restored my own rights I had lost. But from my quick look this morning I will have to drill down thru the disk volumes and folders to restore rights along the way. That's a project for tonight, as well as re-establishing the desktop and running combofix. BTW combofix did not restart my machine when I ran it in safe mode. Will run it in normal mode when I get the desktop back.
And with any luck I'll get superantispyware on the machine as well.0 -
I have deleted a malware user from the registry and from the folders where superantispyware installer is loaded, but still cannot get it to let me install. The app itself still is denying me security rights. The check boxes are disabled and I can't figure out how to enable them. While I was deleting the malware user from security it replicated itself in the security window but eventually I got rid of both.
Also, I'm finding that the unknown user S-1-5-21-plus many digits has propagated itself throughout my security tabs. To delete it I must open the tab, clear the inheritance, and then delete it from each and every folder and file. Do I need to do this? And if so, is there a quick way to do it? I was not surprised to find that this user does not appear in the user accounts control panel.
And still cannot run Superantispyware installer.
Got a desktop with "last known good configuration" but it took an incredibly long time and appears to hang at the point where BitDefender complains that it is shut off, and sets the balloon "click here to resolve the problem." Running explorer.exe in the task manager run menu doesn't seem to do anything, or maybe it just takes a really long time. When I try to shut down, explorer.exe hangs and I have to kill the process. And if I try to click anything in the desktop I get a permanent hourglass.
So still not there. Sheesh.
But really appreciate your help!0 -
Here is combofix log from running it with windows in normal mode. The recovery console somehow got uninstalled, and so I had to run it again after reinstalling.
Combofix seems to run normally but hangs after it opens the log. To get the computer back, I have to open the task manager and do a restart off the menu, and it takes several minutes to get a desktop in normal mode...it used to take only a few seconds.
And thanks for the help!
ComboFix 08-06-04.1 - Julius 2008-06-06 6:20:55.3 - NTFSx86
Running from: E:\Documents and Settings\Julius\Desktop\ComboFix.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-06 to 2008-06-06 )))))))))))))))))))))))))))))))
.
2008-06-03 17:30 . 2008-06-03 17:30 <DIR> d-------- E:\Program Files\Malwarebytes' Anti-Malware
2008-06-03 17:30 . 2008-06-03 17:30 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-03 17:30 . 2008-06-03 17:30 <DIR> d-------- E:\Documents and Settings\Administrator\Application Data\Malwarebytes
2008-06-03 17:30 . 2008-05-30 01:06 34,296 --a------ E:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-03 17:30 . 2008-05-30 01:06 15,864 --a------ E:\WINDOWS\system32\drivers\mbam.sys
2008-06-03 06:27 . 2008-06-03 06:27 <DIR> d---s---- E:\Documents and Settings\Administrator\UserData
2008-05-30 20:49 . 2008-05-30 20:49 <DIR> d-------- E:\Program Files\Spybot - Search & Destroy
2008-05-30 20:49 . 2008-05-30 21:11 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-30 20:26 . 2008-05-30 20:26 <DIR> d-------- E:\Program Files\Windows Defender
2008-05-29 20:16 . 2008-05-29 20:16 <DIR> d-------- E:\Program Files\Lavasoft
2008-05-29 20:16 . 2008-05-29 20:17 <DIR> d-------- E:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-29 20:10 . 2008-06-02 19:20 <DIR> d-------- E:\Program Files\Common Files\Wise Installation Wizard
2008-05-26 12:42 . 2008-05-26 12:42 <DIR> d--hs---- E:\WINDOWS\ftpcache
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ E:\WINDOWS\system32\lsdelete.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-06 00:00 --------- d-----w E:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-05-28 23:57 --------- d-----w E:\Program Files\Mozilla Thunderbird
2008-05-25 13:03 --------- d-----w E:\Program Files\Java
2008-05-24 18:51 --------- d-----w E:\Program Files\SiteAdvisor
2008-05-10 16:38 --------- d-----w E:\Documents and Settings\Julius\Application Data\SiteAdvisor
2008-05-03 19:28 --------- d-----w E:\Documents and Settings\All Users\Application Data\Maxtor
2008-05-03 19:26 --------- d-----w E:\Program Files\Maxtor
2008-05-03 19:25 --------- d--h--w E:\Program Files\InstallShield Installation Information
2008-04-29 15:20 15,648 ----a-w E:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 15:19 15,648 ----a-w E:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 15:19 12,960 ----a-w E:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-12 19:55 --------- d-----w E:\Documents and Settings\All Users\Application Data\Apple Computer
2008-04-11 00:02 --------- d-----w E:\Program Files\NetWaiting
2008-04-10 23:47 --------- d-----w E:\Program Files\Hayes
2008-03-27 08:12 151,583 ----a-w E:\WINDOWS\system32\msjint40.dll
2008-03-19 09:47 1,845,248 ----a-w E:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-04_18.22.20.78 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-04 22:08:45 2,048 --s-a-w E:\WINDOWS\bootstat.dat
+ 2008-06-06 09:55:38 2,048 --s-a-w E:\WINDOWS\bootstat.dat
+ 2008-06-06 09:55:43 16,384 ----atw E:\WINDOWS\TEMP\Perflib_Perfdata_770.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="sttray.exe" []
"IntelAudioStudio"="E:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" [2006-08-02 18:17 9134080]
"DiskeeperSystray"="E:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-02-24 20:29 196709]
"farstone"="" []
"RestoreIT!"="E:\Program Files\FarStone\RestoreIT\RestoreIT_XP\VBPTASK.exe" [2005-04-30 01:09 122880]
"NvCplDaemon"="E:\WINDOWS\system32\NvCpl.dll" [2007-05-11 07:03 8429568]
"nwiz"="nwiz.exe" [2007-05-11 07:03 1626112 E:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="E:\WINDOWS\system32\NvMcTray.dll" [2007-05-11 07:03 81920]
"ipTray.exe"="E:\Program Files\Intel\IDU\iptray.exe" [2006-11-24 13:26 2209792]
"SiteAdvisor"="E:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-12-04 17:03 36640]
"Adobe Reader Speed Launcher"="E:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"BitDefender Antiphishing Helper"="E:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 16:46 61440]
"BDAgent"="E:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-22 19:33 360448]
"XboxStat"="e:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" [2007-09-26 19:05 734264]
"SunJavaUpdateSched"="E:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"IntelliPoint"="E:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2006-11-21 21:09 842584]
"QuickTime Task"="E:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="E:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"MaxtorOneTouch"="E:\Program Files\Maxtor\OneTouch\utils\Onetouch.exe" [2006-03-27 15:04 712704]
"mxomssmenu"="E:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe" [2005-10-17 16:24 81920]
E:\Documents and Settings\All Users\Start Menu\Programs\Startup\
NaturalColorLoad.lnk - E:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2008-02-23 15:20:53 155715]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= E:\PROGRA~1\COMMON~1\ULEADS~1\Vio\Dvacm.acm
"msacm.mpegacm"= mpegacm.acm
"msacm.ulmp3acm"= ulmp3acm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"E:\\Program Files\\iTunes\\iTunes.exe"=
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\setup.exe /autorun
\Shell\directx\command - G:\DirectX\dxsetup.exe
\Shell\setup\command - G:\setup.exe
*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder
"2008-06-06 09:58:42 E:\WINDOWS\Tasks\MP Scheduled Scan.job"
- E:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-06 06:22:29
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-06-06 6:23:02
ComboFix-quarantined-files.txt 2008-06-06 10:22:58
ComboFix2.txt 2008-06-05 23:47:26
ComboFix3.txt 2008-06-04 22:22:33
Pre-Run: 239,047,184,384 bytes free
Post-Run: 239,035,551,744 bytes free
114 --- E O F --- 2008-05-15 18:51:110 -
Hello jfs_1950,
I can't find anything suspecious anymore.
Press the windows button together with r now type regedit press enter. Expand HKEY_LOCAL_MACHINE and open the following subfolders: Software\Policies See if you can find something like Preventrun with as value 1 delete it. It can be located in folder called Superantispyware.
Best regards
Niels0 -
Niels,
Thanks, I will try that (not at that computer at the moment). Is there any way to delete the unknown user from all the security tabs? It has embedded itself all over the place. I don't think it is controlling anything other than the superantivirus, but would like to clear it out anyway.
Also, should I be worried that the windows recovery console got somehow uninstalled? I reinstalled it and it seems stable now, but never saw that happen before.
jfs
Also I note that when I boot in normal mode. BitDefender launches but the neat little windows that show disk and network traffic do not open on the desktop.
And in normal mode, the machine is unbelievably slow. Used to boot to normal mode in <30 seconds, now take literally minutes, and if I put any mouse click or command in, it takes as much as a minute for the machine to respond.
So there are still things going on that need attention.
And thanks again for the help!
crysty2k5's EDIT: posts merged0 -
Hello jfs_1950,
Normally when you have right clicked on HKEY_LOCAL_MACHINE,HKEY_USERS,HKEY_CURRENT_USER,HKEY_CLASSES_ROOT and HKEY_CURRENT_CONFIG and select permissions and deleted the user account or deny all access and rebooted your pc. Be sure that guest account is disable to check that go to start,control panel,user accounts (set the contorl panel on classic view). You must see that guest account is disabled.
Can you please download autoruns? You can find it here.Unzip it and double click on autoruns(.exe) wait till the scan is finished. When it is finished you will see ready now press on the diskette icon and save it and attach the output as attachment to your next post.
Please right click on the red BitDefender icon near the system tray press on open advanced settings. Press on advanced see if enable scan activity bar is checked if not check it and press on ok.
Best regards,
Niels0 -
Hi,
I am fast losing hope that I will be able to recover this machine. It is running slower and slower. The only thing I am able to do in normal mode is open the task manager. If I try to restart from task manager, explorer.exe hangs and I have to manually kill it. The performance tab shows virtually no CPU activity but the machine is not responding to anything right now. In the processes tab I can look at priority for each app, but when I try to set affinity I get an access denied error. This used to be a very fast machine (2ghz Core 2 Duo)
BD is disabled and I am unable to reenable it. Needless to say the machine is disconnected from the network and will remain so for now. Writing this on a different machine.
I was interested to learn that in normal mode, windoze adds a "disable" selection to applications that is not visible in safe mode. Why they would do it that way is beyond me. But anyway, on superantispyware the malware used this button to disable the installer. However the malware seems to have done the same thing to the installer, because it still will not install. The problem is that the machine is now essentially frozen and I can't get to msiexec.exe to check if it was disabled the same way.
I can try to download autoruns.zip, burn it to a CD and run it on the infected machine. I will have to do this from safe mode, because normal mode has become pretty much useless.
Is it a waste of time to run autoruns in safe mode? Any other ideas on getting enough control back that I can at least try?
If I do have to reinstall I wll lose some data, but not much. I back data up to an external hard drive that is turned off except when I am running backups so it is safe. I don't trust windoze to completely clean the drives. I'll wipe the drives clean using ultimate boot CD, one drive at a time with others disconnected so they can't reinfect each other. The main thing is that it is such a pain to reinstall everything.
And thanks again for all your help.0 -
Hello jfs_1950,
See if you can boot normally when you do this: First boot your pc into safe mode. After that press the windows button together with r now type msconfig press enter. Now select Diagnostic Startup. Reboot your pc and see if you now can get into normal mode.
First print what is written here and here.
Please put in your installation cd-rom of BitDefender. Now reboot your pc and follow the instructions that are described in the first link. If you don't have a cd-rom version of BitDefender please download this bootable image of the rescue cd-rom. You have to run it as an bootable disk in your burning program.
Running autoruns in safe mode is almost useless because only a limited of services are loaded.
Best regards
Niels0 -
Hi Niels.
Diagnostic startup brought normal mode up very quickly. I will download the BD rescue disk and work to get my firewall back. Unfortunately I don't have a CD of the version of BD that I am running. A few months ago I had a massive crash due to hardware issues, and then I couldn't get BD to install properly from the CD, so the nice folks at BD authorized me to download the Internet Security 2008 version. But I never got a CD of it. Lesson learned.
Now when I try to install superantispyware I get a different error, which is that the installer service could not be accessed. I'm assuming that it should work in diagnostic mode, so I will attempt to re-register it.
Will get back to you with success or fail on BD rescue and superantispyware.
jfs0 -
Hello jfs_1950,
Follow these instructions for how to re register windows installer. But I suppose that you know how to do that because you already mentioned it.
It could be that superantispyware installation needs a reboot. But because of the diagnostic startup the superantispyware service will not be started. To solve that press the windows button together with r now type services.msc press enter. Now search for services that have superantispyware in the name left click on them and choos start. Keep diagnostic support enabled as long as possible because it's going to be easier for superantispyware and other malware removal tools to remove infections. I advise that you also run a full (deep) scan of superantispyware also in safe mode and normal mode.
I will wait how it's going.
Best regards
Niels0 -
Hello jfs_1950,
Follow these instructions for how to re register windows installer. But I suppose that you know how to do that because you already mentioned it.
It could be that superantispyware installation needs a reboot. But because of the diagnostic startup the superantispyware service will not be started. To solve that press the windows button together with r now type services.msc press enter. Now search for services that have superantispyware in the name left click on them and choos start. Keep diagnostic support enabled as long as possible because it's going to be easier for superantispyware and other malware removal tools to remove infections. I advise that you also run a full (deep) scan of superantispyware also in safe mode and normal mode.
I will wait how it's going.
Best regards
Niels
Hi Niels, the problem with superantispyware isn't the service, because I have never been able to install it. The malware has kept me from doing that. But now, the installer itself doesn't want to respond. However the reboot suggestion is worth a try before I re-register it.
Thanks.
Hi Niels.
Well, I finally got superantispyware installed. Turns out that I did have to re-register the installer, but also had to turn it on using the windows diagnostic settings. I did that with BitDefender also, but cannot make changes to reactivate the firewall and the virus checker.
Tried the rescue disk, both my BD version 9 CD and a downloaded image from the link you sent. Both crash with an error that says that Linux cannot find the Knoppix file system. Sheesh.
Any ideas about how to fix that? In the meantime, I am running a deep scan with superantispyware.
Deep scan in safe mode and diagnostic mode revealed no problems. Also did a manual scan with bitdefender, nothing identified.
So looking for more ideas...thanks for helping me.
crysty2k5's EDIT: posts merged0 -
Hello jfs_1950,
Try this when you booted with the linux cd-rom. Type the following:
knoppix nodma press enter see if you can pass now.
If not try this command:
failsafe press enter or return
I also recommend that you uninstall BitDefender completely by using this tool.
Right click on the red BitDefender icon near the system tray first and press on exit now run the uninstall tool. You will be asked to reboot install BitDefender again.
Can you please run autoruns?
Best regards
Niels0 -
Niels and crysty2k5, thanks for all the help.
Neither knoppix nodma nor failsafe helped with the bitdefender rescue disk. I did uninstall bitdefender though.
I got autoruns installed. I hadn't forgotten about it. Just hadn't run it yet. I ran it...and now I cannot connect to the internet to send the log!!!! Nor can I connect a USB flash drive to move it (reluctantly, since I don't know how safe it is) to another computer to send it!
I tried establishing a new network connection in safe mode with networking and also in diagnostic mode. No joy either way.
So any more ideas? Personally I'm getting closer to a complete reinstall if only because (1) then I'm done with the hassle, and (2) then I can trust the machine as much as I have ever trusted windoze and Bill Gates.
BTW windoze now is telling me that I have made significant hardware changes (which is complete BS, all problems are OS-related software) and I must re-activate in 3 days. Maybe this is the cause of no connectivity. Wouldn't surprise me.
Hey Bill Gates, how about coming to my house and fixing my computer??0 -
Hello jfs_1950,
Personnally if I see that you now even got more problems it's better to restore a previous back-up.The infection might have caused some serious damage. Did Superantispyware detected something?
Or you can still try this put in the windows installation cd-rom. After that press the windows button together with r now type cmd press enter. Afterwards type this sfc /scannow and press enter.
Best regards,
Niels0 -
Hello jfs_1950,
Personnally if I see that you now even got more problems it's better to restore a previous back-up.The infection might have caused some serious damage. Did Superantispyware detected something?
Or you can still try this put in the windows installation cd-rom. After that press the windows button together with r now type cmd press enter. Afterwards type this sfc /scannow and press enter.
Best regards,
Niels
Hi Niels.
Sorry about the outburst in my last post. But I feel like I'm playing whack-a-mole. In any event, tonight I will try the windows installation CD stuff.
To answer your question, no, superantispyware did not reveal anything. Presumably either the malware is something too new for it to recognize, or it got wiped out along the way but trashed the OS before it died.
Even if I restore from backup I'd like to get an autoruns log to you so we can see what is going on.
jfs0 -
Hello jfs_1950,
Can you please download sdfix from here. Double click on it allow it to install in C:\SDFIX
Now reboot your pc into safe by pressing several times on the F8 button before the windows splash screen select safe mode press enter. Log in with your account. Now go to C:\SDFIX and double click on RunThis.bat Type y to start the cleaning process. When it finishes you will be prompted to press any key on your keyboard do that. Once you are in normal mode wait till you see finished and press again any key now you will get back on your desktop. Please post the content of Report into your next reply.
To see if it isn't a rootkit.
Best regards
Niels0 -
Hi Niels.
I ran SDFix and the log showed nothing unusual. I cannot upload the log because the network connections have disappeared from the infected machine. If I try to open the network connections icon, control panel freezes and I have to kill it in the task manager. Also I can no longer reach the device manager. Maybe that is why windoze thinks the hardware configuration is changed.
explorer.exe is no longer stable even in safe mode and I cannot shut down with the start button (an oxymoron, anyway) and must use task manager to restart.
If I could figure out how to send you the logs from SDFix and Autoruns I would, but the machine seems to have permanently isolated itself from the rest of the universe. I am mildly surprised it still accepts a connection to power.
I tried the windows installation disk scan (sdf /scannow) of the protected files. No improvement to the network connection or to to the device manager regardless of boot mode.
Between inability to fix the OS, and Bill Gates pestering me to reactivate which would put a 3 month timer on other major system changes, I can only conclude that it is time for an OS reinstall.
I will wipe the drives down to bare metal with Ultimate Boot CD, one at a time with the others disconnected, so they cannot reinfect each other.
Gonna be a long week as I reinstall everything. At least the vast majority of my data is backed up to an external hard drive which has been shut down through this entire adventure. The lesson to anyone else who reads this is: Back Up Your Data! (To a place where malware CANNOT find it)
I really appreciate both you and crysty2k5 working with me on this. Thanks so much.
jfs0 -
Okay, something strange after I wiped the drives and reinstalled the OS. The mysterious Network Service reappeared. And the BitDefender firewall is showing something marked ".\System" trying to connect to the Internet. It has a red question mark on the icon. I blocked access, and then the Network Service and associated network icon disappeared from the Network Connections control panel.
I tried Googling the .\System but can't bring anything up because the Google search engine ignores special characters. Do you know what this is? Is it benign? Or nasty?
Task Manager is showing several instances of svchost running, associated with this mysterious Network Service. System otherwise seems clean at this point and is running at normal speed.
Thanks for helping!
jfs0 -
Hello jfs_1950,
These .system entries are legit ones. You will see one .system item that opens port 445. That port is used to be able that programs can contact your local area network (lan). Infact it are all legit system processes. I assume that you have unchecked hide system processes once you are in the firewall section more specificly on the traffic tab.
It's absolutely normall that you can see many instances of svchost.exe running in task manager. Here are some services that can run under an svchost.exe process:
BitDefender Threat Scanner
Automatic Windows Updates
Wireless Zero Configuration service (for wireless internet cards/connections)
...
Best regards,
Niels0