PDA

View Full Version : I reformatted, reinstalled XP and I already have what looks like malware



ScooterX3
2007-10-20, 18:00
Yep. My computer was messed up. so I bit the bullet, backed up my personal documents, and now I get this popup every few minutes by 1 of a couple different websites: "Message from local system to user...." ... "REGISTRY DAMAGED AND CORRUPTED" ... "To FIX this problem, go to our website & download our (junk)"... :yuck:

and thus it is. And I didn't even have this before I reformatted my hard drive. Here are my scan reports:

Logfile of HijackThis v1.99.1
Scan saved at 8:35:06 AM, on 10/20/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\soundman.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\taskmgr.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Safer Networking\FileAlyzer\FileAlyzer.exe
C:\Documents and Settings\Loader Clan\My Documents\Downloads\HijackThis!\hijackthis\HijackThis.exe

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SoundMan] soundman.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab


And... my Spybot S&D log is HUGE. So I won't post it.
And do you want my Kaspersky report?

ScooterX3
2007-10-20, 18:36
Kaspersky report:

Friday, October 19, 2007 11:53:47 PM
Operating System: Microsoft Windows XP Home Edition, (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 20/10/2007
Kaspersky Anti-Virus database records: 441377
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
H:\
Scan Statistics
Total number of scanned objects 11949
Number of viruses found 0
Number of infected objects 0
Number of suspicious objects 0
Duration of the scan process 00:08:48

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Loader Clan\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\cert8.db Object is locked skipped
C:\Documents and Settings\Loader Clan\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\history.dat Object is locked skipped
C:\Documents and Settings\Loader Clan\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\key3.db Object is locked skipped
C:\Documents and Settings\Loader Clan\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\parent.lock Object is locked skipped
C:\Documents and Settings\Loader Clan\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Loader Clan\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Loader Clan\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Application Data\Mozilla\Firefox\Profiles\zxik9187.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\History\History.IE5\MSHist012007101920071020\index.dat Object is locked skipped
C:\Documents and Settings\Loader Clan\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Loader Clan\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Loader Clan\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\_restore{2D248D80-58A2-4107-AA55-57274E760166}\RP2\change.log Object is locked skipped
C:\WINDOWS\Debug\oakley.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
Scan process completed.

... and my Spybot report came out clean (after deleting all red items)

pskelley
2007-10-24, 16:10
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.
Please make sure you have read this information so we are on the same page.

Nothing is showing in Kaspersky or the HJT log. What is showing is this:
Logfile of HijackThis v1.99.1
Scan saved at 8:35:06 AM, on 10/20/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Read the instructions and you will read this:
You and Windows, a joint effort

If your Operating System is XP without a Service Pack

Thanks

pskelley
2007-11-01, 17:16
This topic is closed due to lack of a response.

If you need it re-opened please send me or a forum staff member a private message (pm) and provide a link to the thread; this applies only to the original topic starter.

Anyone else with similar problems please start a new topic.

Thanks