View Full Version : Trojan Horse (WXP-Pro)
Hello.
I'm using Windows Xp Pro and i got one of my files
(C:\WINDOWS\system32\SysReg.exe) was infected with Trojan Horse.
I have Norton Antivirus, and i tried to scan the folder with that file and it it found it, but it was unable to repare,delete or quarantine the file.
If anyone knows what can i do, please help me.
Thanks in advance.
Gordon7000
05-23-2003, 07:17 AM
Hi xman,
This is CCInvader2 Backdoor Trojan. I know you've already used your own AV program, but would you do this please: go to the online virus scanner below and run a full system scan.
http://www.pandasoftware.com/activescan/com/
Let us know how you get on. There are some files on your Windows system that may need to be deleted manually.
Regards, Gordon
Thank you Gordon for your help.
I scanned my system online and it said no viruses have been found:(.
If u know something else i could do to solve this problem, please let me know.
Thanks again for trying to help me.
Gordon7000
05-24-2003, 12:07 AM
Hi xman,
The online virus scanner that I linked you to, specifically recognises and identifies this particular trojan. So if the online scanner confirms that your PC is clean, it looks like your Norton AV has safely disabled this trojan. However, it's still necessary to remove the executable and any registry entries that could be reactivated.
Go to your C:\WINDOWS\System32 folder. Look for the file, SysReg.exe, and delete it. If Windows tells you the file is in use, delete it in Safe Mode.
Next, download, unzip and run HijackThis:
http://www.spywareinfo.com/~merijn/files/hijackthis.zip
Most of the entries in the log are harmless, so DO NOT fix anything yet. Just SCAN your computer. When the scan is completed, press the SAVE LOG button, then copy and post the log to this forum.
Also, while running HijackThis, press "Config..." > "Misc Tools" > Generate StartupList Log." Post this log to the forum as well, and someone will let you know what to do next.
These logs will help us to ensure that there are no harmful remnants of this trojan still on your PC.
Regards, Gordon
Hello.
Thank you Gordon for helping me.
After online scan, Norton still said that SysReg.exe is infected.
So as you said, i deleted it in a safe mode.
Then i downlaoded the program and did scan.
But something is still using my internet connection, even if all programs that i know could use it are closed.
Here are the logs i got:
Logfile of HijackThis v1.94.0
Scan saved at 5:27:24 PM, on 5/24/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.dothesearch.com/user/sidetemp.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1D870C86-AA3C-4451-81E4-71D480A1A652} - C:\WINDOWS\System32\SbSrch_V22.dll
O2 - BHO: (no name) - {31995C64-CB4D-483E-82C2-CCFFE2F66CAB} - (no file)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QD FastAndSafe] C:\PROGRA~1\NORTON~1\NORTON~2\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ICQ Plus] "C:\Program Files\ICQPlus\vplus.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [SysReg] C:\WINDOWS\System32\SysReg
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Allow popups - file://C:\Program Files\Ultimate Popup Killer\Popupkiller.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O10 - Broken Internet access because of LSP provider 'csloa.dll' missing
O15 - Trusted Zone: http://free.aol.com
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {53E10C2C-43B2-4657-BA29-AAE179E7D35C} - http://207.44.176.11/auth/IE_InstllC.exe
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camserv.base.1plus1.net/AxisCamControl.ocx
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab
==============================
And startup list here:
StartupList report, 5/24/2003, 5:27:35 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\xman\My Documents\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\ICQPlus\vplus.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\pctspk.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navw32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\xman\My Documents\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
C-Media Mixer = Mixer.exe /startup
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
NeroCheck = C:\WINDOWS\system32\NeroCheck.exe
QD FastAndSafe = C:\PROGRA~1\NORTON~1\NORTON~2\QDCSFS.exe /scheduler
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ICQ Plus = "C:\Program Files\ICQPlus\vplus.exe"
ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
ATI Launchpad =
TransparentIcons =
BlockAds =
Tweak-XP =
TransTask =
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
SysReg = C:\WINDOWS\System32\SysReg
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\WINDOWS\System32\SbSrch_V22.dll - {1D870C86-AA3C-4451-81E4-71D480A1A652}
(no name) - (no file) - {31995C64-CB4D-483E-82C2-CCFFE2F66CAB}
(no name) - c:\windows\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
NAV Helper - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer.job
Norton SystemWorks One Button Checkup.job
Symantec NetDetect.job
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
[{53E10C2C-43B2-4657-BA29-AAE179E7D35C}]
CODEBASE = http://207.44.176.11/auth/IE_InstllC.exe
[{8EDAD21C-3584-4E66-A8AB-EB0E5584767D}]
CODEBASE = http://toolbar.google.com/data/GoogleActivate.cab
[CamImage Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\AxisCamControl.ocx
CODEBASE = http://camserv.base.1plus1.net/AxisCamControl.ocx
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab
--------------------------------------------------
Enumerating Winsock LSP files:
Protocol #1: CSLOA.DLL (file MISSING)
Protocol #2: CSLOA.DLL (file MISSING)
Protocol #3: CSLOA.DLL (file MISSING)
Protocol #4: CSLOA.DLL (file MISSING)
Protocol #5: CSLOA.DLL (file MISSING)
Protocol #6: CSLOA.DLL (file MISSING)
Protocol #7: CSLOA.DLL (file MISSING)
Protocol #8: CSLOA.DLL (file MISSING)
Protocol #9: CSLOA.DLL (file MISSING)
Protocol #10: CSLOA.DLL (file MISSING)
Protocol #11: CSLOA.DLL (file MISSING)
Protocol #17: CSLOA.DLL (file MISSING)
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 6,786 bytes
Report generated in 0.141 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Thank you again Gordon for your time.
If anybody knows what i should do next please help me.
Thanks.
Gordon7000
05-25-2003, 03:38 AM
Hi xman,
Yes, your log show that a few things need to be repaired. To begin with, you have the parasitic toolbar, SubSearch (SbSearch). To remove this and other malware, could you download Spybot Search and Destroy:
http://security.kolla.de/index.php?lang=en&page=download
Before using the program, click "Online" and install all updates.
Now, close all web browser windows and disconnect from the Internet.
Then run Spybot (click "Check for Problems").
When the results appear, tick everything highlighted in red.
DELETE all entries in red using Spybot.
After this, REBOOT your PC.
Spybot may appear to 'hang' at certain points. Please allow it several minutes to continue the scan, as it may be carrying out some extensive file checking at these points.
Sometimes, Spybot will show a dialogue box, asking that you run the utility again - after rebooting your PC. If you see this box, click "Yes". Then, after running Spybot a second time, reboot your PC again and check once more to ensure that there are no red items remaining.
CAUTION: Don't use the 'Immunize' feature until you're more familiar with Spybot S&D.
Note for all users: Spybot installation and basic setup tutorial available here (if required):
http://tomcoyote.org/SPYBOT/
Note for advanced users: Spybot advanced user information available here:
http://tomcoyote.org/~mosaic1/spybot/
Once you've finished with Spybot, reboot your PC. Then, close your Internet connection and browser. Run HijackThis again. Check each of the items listed below and get HT to 'Fix checked'.
(Note that some of these items may already have been repaired and removed from the list by Spybot.)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar=http://www.dothesearch.com/user/sidetemp.htm
O2 - BHO: (no name) - {1D870C86-AA3C-4451-81E4-71D480A1A652} - C:\WINDOWS\System32\SbSrch_V22.dll
O2 - BHO: (no name) - {31995C64-CB4D-483E-82C2-CCFFE2F66CAB} - (no file)
O4 - HKCU\..\Run: [SysReg] C:\WINDOWS\System32\SysReg
O10 - Broken Internet access because of LSP provider 'csloa.dll' missing [This one indicates that you've had New.Net or Webhancer in the past.]
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://camserv.base.1plus1.net/AxisCamControl.ocx
Remove AOL from your Trusted Zone in Internet Explorer.
O15 - Trusted Zone: http://free.aol.com
Now, reboot your PC again.
Next, go to C:\WINDOWS\system32 and look for the file, SbSrch_V22.dll. Delete this DLL, in Safe Mode (Safe Boot) if necessary.
Check your C:\WINDOWS\System32 folder again, to ensure that the file, SysReg.exe has not re-installed itself. If you find it, delete it again - in Safe Mode.
(I see that SysReg.exe autoruns from the registry. If it keeps re-installing itself, we'll probably need to delete the registry entries. But we'll check out a new log first.)
Now, reboot your PC once more. Run HijackThis again and post a new HijackThis log AND StartupList log to the forum. If anything still needs to be fixed, someone here will let you know.
BTW, I note that you are using the Google Toolbar, so I haven't included this in the items to be repaired or removed. (If necessary, this can always be done at a later stage.) Google is an excellent search engine, but you may want to have a look at this article indicating some security/privacy concerns with their Toolbar:
http://www.pcmag.com/article2/0,4149,904096,00.asp
Regards, Gordon
<P ID="edit"><FONT class="small"><EM>Edited by Gordon7000 on 05/25/03 02:40.</EM></FONT></P><P ID="edit"><FONT class="small">Edited by Gordon7000 on 05/25/03 02:45.</FONT></P>
Hi Gordon.
Thank you so much for your time.
I really apreciate your help.
I had Spybot Search&Destroy before, and i scanned my PC very often with it, but i never closed connection.I also have Ad-Aware, but i guess it's not really that good, it doesn't detect errors that Spybot S&D finds.
So I did everything like you wrote.
And did HijackThis scan, here are the results of scan.
Logfile of HijackThis v1.94.0
Scan saved at 12:00:27 PM, on 5/26/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=%SystemRoot%\system32\blank.htm
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\windows\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\windows\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QD FastAndSafe] C:\PROGRA~1\NORTON~1\NORTON~2\QDCSFS.exe /scheduler
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKCU\..\Run: [ICQ Plus] "C:\Program Files\ICQPlus\vplus.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: &Google Search - res://C:\WINDOWS\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Allow popups - file://C:\Program Files\Ultimate Popup Killer\Popupkiller.html
O8 - Extra context menu item: Backward &Links - res://C:\WINDOWS\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\WINDOWS\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\WINDOWS\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page - res://C:\WINDOWS\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {53E10C2C-43B2-4657-BA29-AAE179E7D35C} - http://207.44.176.11/auth/IE_InstllC.exe
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab
StartupList report, 5/26/2003, 12:01:39 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\xman\My Documents\HijackThis.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\ICQPlus\vplus.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\pctspk.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\ccPxySvc.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\Documents and Settings\xman\My Documents\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
C-Media Mixer = Mixer.exe /startup
ccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
ccRegVfy = "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
NeroCheck = C:\WINDOWS\system32\NeroCheck.exe
QD FastAndSafe = C:\PROGRA~1\NORTON~1\NORTON~2\QDCSFS.exe /scheduler
QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime
TkBellExe = C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ICQ Plus = "C:\Program Files\ICQPlus\vplus.exe"
ctfmon.exe = C:\WINDOWS\System32\ctfmon.exe
ATI Launchpad =
TransparentIcons =
BlockAds =
Tweak-XP =
TransTask =
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - c:\windows\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
NAV Helper - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll - {BDF3E430-B101-42AD-A544-FADC6B084872}
--------------------------------------------------
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer.job
Norton SystemWorks One Button Checkup.job
Symantec NetDetect.job
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\Macromed\Director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
[{41F17733-B041-4099-A042-B518BB6A408C}]
CODEBASE = http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
[{53E10C2C-43B2-4657-BA29-AAE179E7D35C}]
CODEBASE = http://207.44.176.11/auth/IE_InstllC.exe
[{8EDAD21C-3584-4E66-A8AB-EB0E5584767D}]
CODEBASE = http://toolbar.google.com/data/GoogleActivate.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash5r42.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 5,976 bytes
Report generated in 0.125 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
And yes I'm using Google Toolbar, sometimes its very usefull tool in finiding info, and thats the only one way i know how to check web pages Page Rank. Too bad they don't leave privacy to their users :( .
If there's something wrong with my new logs, somebody please let me know.
Gordon thank so very much for you helping me:)
And this is a great forum to get some advice.
Best regards,
xman.
Gordon7000
05-27-2003, 02:02 AM
Hi xman,
I can't see any sign of that trojan in your latest logs. The logs look clean, except for this parasite:
O16 - DPF: {53E10C2C-43B2-4657-BA29-AAE179E7D35C} - http://207.44.176.11/auth/IE_InstllC.exe
Close down your Internet connection. Run HijackThis and get HT to fix the item above.
The one below is optional.
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
There have been a number of security concerns with RealOne and it's auto-updater. If you want to maximise your Internet security, you might want to get HT to fix the O4 entry. Alternatively, you can disable auto-updates from within the RealOne program itself. You can always update RealOne manually when required.
Now, reboot your PC.
I think it would be a good idea to keep Ad-aware 6 in addition to Spybot S&D, and update them both regularly. Occasionally, Ad-aware 6 identifies malicious components that have not yet been added to the Spybot database.
If you have any further problems, just let the forum know. Someone here will always be very happy to help resolve any problems you may have.
Regards, Gordon
Hi Gordon.
Thank you so much for your time and help.
I removed evrything like you said, and I hope my problem is solved now:).
If i have some troubles, I'll post here, hope someone will help me.
I really apreciate your hellp so much, at first I wanted to format my hard drive and reinstall everything again, but with your help i could fix.
Thanks a lot ;)
Best regards,
xman.
Gordon7000
05-29-2003, 01:41 AM
No problems at all, xman. It's a pleasure to help. Come back any time you need help in the future. The forum members will be more than willing to assist you.
Regards, Gordon
Powered by vBulletin™ Version 4.1.0 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.