PDA

View Full Version : another virtumonde infection



jeremyb
2008-05-01, 17:52
I don't get why none of the tools I've tried will fix it for good. I've been working on this for over a week... guess it's time I beg for help from the experts. I would appreciate any help you can offer. Thanks in advance

ComboFix 08-04-27.3 - fayshe 2008-05-01 11:32:04.4 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.17 [GMT -4:00]
Running from: C:\Documents and Settings\FAYSHE\Desktop\ComboFix.exe
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((( Files Created from 2008-04-01 to 2008-05-01 )))))))))))))))))))))))))))))))
.

2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 15:20 . 08-04-28 15:20 <DIR> d-------- C:\Program Files\CCleaner
2008-04-24 09:34 . 08-04-24 09:34 <DIR> d-------- C:\VundoFix Backups
2008-04-21 14:47 . 08-04-21 14:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-21 14:47 . 08-04-21 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 14:46 . 08-04-21 14:46 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 14:35 . 08-04-21 15:36 67,645 --a------ C:\WINNT\system32\drivers\pshook11.sys
2008-04-21 14:32 . 08-04-21 15:42 <DIR> d-------- C:\Program Files\INAC
2008-04-16 14:40 . 03-06-19 12:05 21,552 --a--c--- C:\WINNT\system32\dllcache\usbstor.sys
2008-04-16 14:27 . 08-04-16 14:27 118 --a------ C:\WINNT\system32\MRT.INI
2008-04-16 14:23 . 08-04-16 14:23 <DIR> d-------- C:\WINNT\system32\Windows Media
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\WINNT\msiinst.tmp
2008-04-16 14:22 . 08-04-16 14:23 <DIR> d--h-c--- C:\WINNT\$NtUpdateRollupPackUninstall$
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-16 14:21 . 08-04-16 14:21 <DIR> d--h-c--- C:\WINNT\$SQLUninstallMDAC25SP3-KB927779-x86-ENU$
2008-04-16 14:19 . 08-04-16 14:19 <DIR> d-------- C:\WINNT\mui
2008-04-16 14:19 . 08-04-16 14:19 957 --a------ C:\WINNT\setup.inf
2008-04-16 14:19 . 08-04-16 14:19 283 --a------ C:\WINNT\setup.rpt
2008-04-16 14:14 . 02-08-29 07:14 44,032 -----c--- C:\WINNT\system32\dllcache\msxml3r.dll
2008-04-16 13:59 . 08-04-16 13:59 <DIR> d-------- C:\WINNT\system32\BITS
2008-04-16 12:10 . 08-04-16 12:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-16 12:10 . 08-04-16 12:13 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 12:04 . 08-04-16 12:05 <DIR> d--h----- C:\WINNT\msdownld.tmp
2008-04-16 12:02 . 07-07-30 19:19 549,720 --a------ C:\WINNT\system32\wuapi.dll
2008-04-16 12:02 . 07-07-30 19:19 325,976 --a------ C:\WINNT\system32\wucltui.dll
2008-04-16 12:02 . 07-07-30 19:19 43,352 --a------ C:\WINNT\system32\wups2.dll
2008-04-16 12:02 . 07-07-30 19:18 34,136 --a------ C:\WINNT\system32\wucltui.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 33,624 --a------ C:\WINNT\system32\wups.dll
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuaucpl.cpl.mui
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuapi.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 20,312 --a------ C:\WINNT\system32\wuaueng.dll.mui
2008-04-03 16:41 . 08-04-03 16:41 120,868 --a------ C:\WINNT\system32\MSForms.TWD

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 09:26 1,644,080 ----a-w C:\WINNT\system32\WIN32K.SYS
2008-02-19 17:08 236,304 ----a-w C:\WINNT\system32\GDI32.DLL
2008-02-15 15:17 575,488 ----a-w C:\WINNT\system32\WININET.DLL
2008-02-15 13:24 96,528 ----a-w C:\WINNT\system32\dnsrslvr.dll
2004-04-14 21:38 271 ---h--w C:\Program Files\desktop.ini
2004-04-14 21:38 21,952 ---h--w C:\Program Files\folder.htt
2003-07-14 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((( snapshot@Mon 2008-04-28_15.11.20.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-11 13:41:36 345,656 ----a-w C:\WINNT\Downloaded Program Files\ewidoOnlineScan.dll
- 2008-04-28 19:07:55 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2008-05-01 15:34:21 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 135,251 2003-09-18 08:01:00 C:\ePOAgent\bak\UpdaterUI.exe

----a-w 249,856 2003-10-02 08:44:32 C:\WINNT\system32\bak\keyhook.exe

----a-w 667,648 2003-10-02 08:45:16 C:\WINNT\system32\bak\sistray.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B534EF37-A8FF-4F82-887F-33CDC1D47110}]
08-04-16 10:46 315712 --a------ C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-07-14 08:00 111376 C:\WINNT\system32\mobsync.exe]
"SiS Windows KeyHook"="C:\WINNT\system32\keyhook.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [03-10-08 05:41 57344 C:\WINNT\SOUNDMAN.EXE]
"McAfeeUpdaterUI"="C:\ePOAgent\UpdaterUI.exe" [ ]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [04-09-22 08:00 98304]
"INACASAP"="C:\Program Files\INAC\Anti Spyware\inac2.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-07-14 08:00 186640]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-06 02:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-06 02:00:00 51984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll

R1 SiSEsc;SISLIB_ESC;C:\WINNT\system32\sisesc.sys [03-08-18 01:21 ]
R3 EntDrv50;EntDrv50;C:\WINNT\system32\drivers\EntDrv50.sys [07-01-18 20:00 ]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-07-14 08:00 ]
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 08:05 ]

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-01 11:44:16
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINNT\system32\Perflib_Perfdata_32c.dat 16384 bytes

scan completed successfully
hidden files: 1

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AxPsHook11]
"ImagePath"="\??\"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINNT\system32\lsass.exe
-> C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll

PROCESS: C:\WINNT\explorer.exe
-> C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
.
Completion time: 2008-05-01 11:46:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-01 15:45:52
ComboFix2.txt 2008-04-29 14:23:09
ComboFix3.txt 2008-04-28 19:42:08
ComboFix4.txt 2008-04-28 19:12:01

Pre-Run: 37,621,755,904 bytes free
Post-Run: 37,616,291,840 bytes free

123

Blade81
2008-05-02, 08:53
Hi

First of all you shouldn't twiddle with ComboFix without supervision! You can mess things up badly with it if you're not 100% sure you know what you're doing.



Open notepad and copy/paste the text in the quotebox below into it:



File::
C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B534EF37-A8FF-4F82-887F-33CDC1D47110}]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages=hex(7):6d,73,76,31,5f,30,00,00



Save this as
CFScript


http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif

Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.


Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.


Download ATF (Atribune Temp File) Cleaner© by Atribune (http://www.atribune.org/ccount/click.php?id=1) to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.


Please run an online scan with Kaspersky Online Scanner (http://www.kaspersky.com/downloads/kws/kavwebscan.html). You will be prompted to install an ActiveX component from Kaspersky, click Yes.
The program will launch and start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings and select the following:
Scan using the following Anti-Virus database:
Extended (If available, otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK.
Under
select a target to scan
, select My Computer.
The scan will take a while so be patient and let it run. As it scans your machine very deeply it could take hours to complete, Kaspersky suggests running it during a time of low activity.Once the scan is complete:
Click on the Save as Text button.
Save the file to your desktop.
Copy and paste that information into your next post if the AV content will fit into one post only. Post a fresh hjt log too and don't forget above meantioned ComboFix log.


Note for Internet Explorer 7 users: If at any time you have trouble with the Accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.

If having a problme doing the above

Make sure that your Internet security settings are set to default values.

To set default security settings for Internet Explorer:

* Open Internet Explorer.
* Go to the Tools menu, then choose Internet Options.
* Click on the Security tab.
* Make sure that all four item (Internet, Local intranet, Trusted sites, and Restricted sites) are set to their default settings.

jeremyb
2008-05-02, 21:11
Thanks for the help, it is apprectiated. I tried running that script and get the following error in a Registry Editor dialog box

Cannot import "blah blah (path to script's location)CFScript: The specified file is not a registry script. You can import only registry files.


Am I doing something wrong here???

Thanks

Jeremy

Blade81
2008-05-02, 22:42
Hi Jeremy

Please try running CFScript again. This time write down complete error message if you still get one.

jeremyb
2008-05-02, 22:57
I tried it three or four times with the same result. The only thing I left out of the error message is the path to where the CFScript and Combofix.exe are located which is

C:\documents and settings\FAYSHE\Destop\CFScript

and one time it was

C:\documents and settings\FAYSHE\Destop\CFScript.txt

because I wanted to try it with the "txt" extension to see if that helped.

Blade81
2008-05-03, 12:58
Hi

Please post contents of current c:\combofix\combofix.txt file.

jeremyb
2008-05-05, 19:21
Here you go.... thanks again!!!

ComboFix 08-04-27.3 - fayshe 2008-05-05 13:07:31.7 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.28 [GMT -4:00]
Running from: C:\Documents and Settings\FAYSHE\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\FAYSHE\Desktop\CFScript.txt
* Resident AV is active


WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll

.
((((((((((((((((((((((((( Files Created from 2008-04-05 to 2008-05-05 )))))))))))))))))))))))))))))))
.

2008-05-02 14:45 . 08-05-02 14:45 376,132 ---h----- C:\WINNT\ShellIconCache
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\WINNT\system32\Kaspersky Lab
2008-05-01 10:28 . 08-05-01 10:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-28 15:20 . 08-04-28 15:20 <DIR> d-------- C:\Program Files\CCleaner
2008-04-24 09:34 . 08-04-24 09:34 <DIR> d-------- C:\VundoFix Backups
2008-04-21 14:47 . 08-04-21 14:47 <DIR> d-------- C:\Program Files\Lavasoft
2008-04-21 14:47 . 08-04-21 14:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-04-21 14:46 . 08-04-21 14:46 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-04-21 14:35 . 08-04-21 15:36 67,645 --a------ C:\WINNT\system32\drivers\pshook11.sys
2008-04-21 14:32 . 08-04-21 15:42 <DIR> d-------- C:\Program Files\INAC
2008-04-16 14:40 . 03-06-19 12:05 21,552 --a--c--- C:\WINNT\system32\dllcache\usbstor.sys
2008-04-16 14:27 . 08-04-16 14:27 118 --a------ C:\WINNT\system32\MRT.INI
2008-04-16 14:23 . 08-04-16 14:23 <DIR> d-------- C:\WINNT\system32\Windows Media
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\WINNT\msiinst.tmp
2008-04-16 14:22 . 08-04-16 14:23 <DIR> d--h-c--- C:\WINNT\$NtUpdateRollupPackUninstall$
2008-04-16 14:22 . 08-04-16 14:22 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-16 14:21 . 08-04-16 14:21 <DIR> d--h-c--- C:\WINNT\$SQLUninstallMDAC25SP3-KB927779-x86-ENU$
2008-04-16 14:19 . 08-04-16 14:19 <DIR> d-------- C:\WINNT\mui
2008-04-16 14:19 . 08-04-16 14:19 957 --a------ C:\WINNT\setup.inf
2008-04-16 14:19 . 08-04-16 14:19 283 --a------ C:\WINNT\setup.rpt
2008-04-16 14:14 . 02-08-29 07:14 44,032 -----c--- C:\WINNT\system32\dllcache\msxml3r.dll
2008-04-16 13:59 . 08-04-16 13:59 <DIR> d-------- C:\WINNT\system32\BITS
2008-04-16 12:10 . 08-04-16 12:10 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-16 12:10 . 08-04-16 12:13 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-16 12:04 . 08-04-16 12:05 <DIR> d--h----- C:\WINNT\msdownld.tmp
2008-04-16 12:02 . 07-07-30 19:19 549,720 --a------ C:\WINNT\system32\wuapi.dll
2008-04-16 12:02 . 07-07-30 19:19 325,976 --a------ C:\WINNT\system32\wucltui.dll
2008-04-16 12:02 . 07-07-30 19:19 43,352 --a------ C:\WINNT\system32\wups2.dll
2008-04-16 12:02 . 07-07-30 19:18 34,136 --a------ C:\WINNT\system32\wucltui.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 33,624 --a------ C:\WINNT\system32\wups.dll
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuaucpl.cpl.mui
2008-04-16 12:02 . 07-07-30 19:19 25,944 --a------ C:\WINNT\system32\wuapi.dll.mui
2008-04-16 12:02 . 07-07-30 19:18 20,312 --a------ C:\WINNT\system32\wuaueng.dll.mui

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 09:26 1,644,080 ----a-w C:\WINNT\system32\WIN32K.SYS
2008-02-19 17:08 236,304 ----a-w C:\WINNT\system32\GDI32.DLL
2008-02-15 15:17 575,488 ----a-w C:\WINNT\system32\WININET.DLL
2008-02-15 13:24 96,528 ----a-w C:\WINNT\system32\dnsrslvr.dll
2004-04-14 21:38 271 ---h--w C:\Program Files\desktop.ini
2004-04-14 21:38 21,952 ---h--w C:\Program Files\folder.htt
2003-07-14 12:00 32,528 ----a-w C:\WINNT\inf\wbfirdma.sys
.

((((((((((((((((((((((((((((( snapshot@Mon 2008-04-28_15.11.20.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-07-11 13:41:36 345,656 ----a-w C:\WINNT\Downloaded Program Files\ewidoOnlineScan.dll
- 2008-04-28 19:07:55 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2008-05-05 17:10:01 3,103 ----a-w C:\WINNT\system32\HPANT.DAT
+ 2005-05-24 16:27:16 213,048 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
+ 2007-08-29 19:47:20 94,208 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
+ 2007-08-29 19:49:54 950,272 ----a-w C:\WINNT\system32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
----a-w 135,251 2003-09-18 08:01:00 C:\ePOAgent\bak\UpdaterUI.exe

----a-w 249,856 2003-10-02 08:44:32 C:\WINNT\system32\bak\keyhook.exe

----a-w 667,648 2003-10-02 08:45:16 C:\WINNT\system32\bak\sistray.EXE

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [03-07-14 08:00 111376 C:\WINNT\system32\mobsync.exe]
"SiS Windows KeyHook"="C:\WINNT\system32\keyhook.exe" [ ]
"SoundMan"="SOUNDMAN.EXE" [03-10-08 05:41 57344 C:\WINNT\SOUNDMAN.EXE]
"McAfeeUpdaterUI"="C:\ePOAgent\UpdaterUI.exe" [ ]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [04-09-22 08:00 98304]
"INACASAP"="C:\Program Files\INAC\Anti Spyware\inac2.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe" [03-07-14 08:00 186640]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Microsoft Find Fast.lnk - C:\Program Files\Microsoft Office\Office\FINDFAST.EXE [1997-08-06 02:00:00 111376]
Office Startup.lnk - C:\Program Files\Microsoft Office\Office\OSA.EXE [1997-08-06 02:00:00 51984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= mmdrv.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\yayaaBqo.dll

R1 SiSEsc;SISLIB_ESC;C:\WINNT\system32\sisesc.sys [03-08-18 01:21 ]
R3 EntDrv50;EntDrv50;C:\WINNT\system32\drivers\EntDrv50.sys [07-01-18 20:00 ]
R3 openhci;Microsoft USB Open Host Controller Driver;C:\WINNT\system32\DRIVERS\openhci.sys [03-07-14 08:00 ]
R3 usbhub20;USB 2.0 Root Hub Support;C:\WINNT\system32\DRIVERS\usbhub20.sys [03-06-19 08:05 ]

.
**************************************************************************

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-05 13:12:42
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AxPsHook11]
"ImagePath"="\??\"
.
Completion time: 2008-05-05 13:14:17 - machine was rebooted [fayshe]
ComboFix-quarantined-files.txt 2008-05-05 17:14:06
ComboFix2.txt 2008-05-02 18:30:24
ComboFix3.txt 2008-05-02 18:04:14
ComboFix4.txt 2008-05-01 15:46:06
ComboFix5.txt 2008-04-29 14:23:09

Pre-Run: 37,615,460,352 bytes free
Post-Run: 37,612,507,136 bytes free

122

Blade81
2008-05-05, 20:45
Hi


Save text below as fix.reg on Notepad (save it as all files (*.*)) on the Desktop.


REGEDIT4

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages=hex(7):6d,73,76,31,5f,30,00,00


It should look like this -> http://users.telenet.be/bluepatchy/miekiemoes/images/reg.gif

Doubleclick fix.reg, press Yes and ok.

(In case you are unsure how to create a reg file, take a look here (http://www.nellie2.co.uk/file.htm#How_to_Make_a_.Reg_File_) with screenshots.)


After that please post a fresh hjt log and Kaspersky report after doing the scan I meantioned in post #2.

jeremyb
2008-05-05, 21:13
OK, did everything you said (still got that error that I mentioned above though)

Here is my HJT log (I'll run the other one now and post it next)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:13, on 2008-05-05
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\system32\svchost.exe
C:\ePOAgent\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\FAYSHE\Desktop\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\system32\keyhook.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\ePOAgent\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [INACASAP] C:\Program Files\INAC\Anti Spyware\inac2.exe /h
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hartson-kennedy.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBAF6C6B-4DD6-4082-8F1D-09923D092AE0}: NameServer = 204.242.1.21,204.242.1.24
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hartson-kennedy.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hartson-kennedy.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\ePOAgent\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

--
End of file - 4147 bytes

jeremyb
2008-05-05, 21:44
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-05-05 15:42
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 5/05/2008
Kaspersky Anti-Virus database records: 741235
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - Critical Areas:
C:\WINNT
C:\DOCUME~1\FAYSHE\LOCALS~1\Temp\

Scan Statistics:
Total number of scanned objects: 7499
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 00:08:43

Infected Object Name / Virus Name / Last Action
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped

Scan process completed.

Blade81
2008-05-06, 06:21
Hi

Please do Kaspersky scan as instructed (full scan). Post its report & a fresh hjt log. Let me also know how's the system running.

jeremyb
2008-05-06, 15:46
I thought I did the correct Kaspersky scan... just did it again. Here is the log.

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
2008-05-06 09:36
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 6/05/2008
Kaspersky Anti-Virus database records: 742239
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
H:\

Scan Statistics:
Total number of scanned objects: 17554
Number of viruses found: 1
Number of infected objects: 0
Number of suspicious objects: 2
Duration of the scan process: 00:19:58

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20080505_Time-150213609_EnterceptExceptions.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\BOPDATA\_Date-20080505_Time-150213609_EnterceptRules.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\Agent_FAYSHE.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\Common Framework\Db\PrdMgr_FAYSHE.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\AccessProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\BufferOverflowProtectionLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Network Associates\VirusScan\OnAccessScanLog.txt Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver.zip/MTE3NDI6ODoxNgnew.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\FAYSHE\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\FAYSHE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\FAYSHE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\FAYSHE\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\FAYSHE\Local Settings\History\History.IE5\MSHist012008050620080507\index.dat Object is locked skipped
C:\Documents and Settings\FAYSHE\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\FAYSHE\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\FAYSHE\NTUSER.DAT.LOG Object is locked skipped
C:\quarantine\abc123cDyG.exe.Vir Object is locked skipped
C:\quarantine\abc123sH33a.exe.Vir Object is locked skipped
C:\quarantine\abc123YG8aa.exe.Vir Object is locked skipped
C:\quarantine\Av-test.txt.Vir Object is locked skipped
C:\quarantine\Av-test.txt.Vir.0 Object is locked skipped
C:\quarantine\Av-test.txt.Vir.1 Object is locked skipped
C:\quarantine\Av-test.txt.Vir.2 Object is locked skipped
C:\quarantine\Av-test.txt.Vir.3 Object is locked skipped
C:\quarantine\Av-test.txt.Vir.4 Object is locked skipped
C:\quarantine\Av-test.txt.Vir.5 Object is locked skipped
C:\WINNT\CSC\00000001 Object is locked skipped
C:\WINNT\Debug\ipsecpa.log Object is locked skipped
C:\WINNT\Debug\Netlogon.log Object is locked skipped
C:\WINNT\Debug\oakley.log Object is locked skipped
C:\WINNT\Debug\PASSWD.LOG Object is locked skipped
C:\WINNT\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINNT\system32\config\AppEvent.Evt Object is locked skipped
C:\WINNT\system32\config\default Object is locked skipped
C:\WINNT\system32\config\default.LOG Object is locked skipped
C:\WINNT\system32\config\SAM Object is locked skipped
C:\WINNT\system32\config\SAM.LOG Object is locked skipped
C:\WINNT\system32\config\SecEvent.Evt Object is locked skipped
C:\WINNT\system32\config\SECURITY Object is locked skipped
C:\WINNT\system32\config\SECURITY.LOG Object is locked skipped
C:\WINNT\system32\config\software Object is locked skipped
C:\WINNT\system32\config\software.LOG Object is locked skipped
C:\WINNT\system32\config\SysEvent.Evt Object is locked skipped
C:\WINNT\system32\config\system Object is locked skipped
C:\WINNT\system32\config\SYSTEM.ALT Object is locked skipped
C:\WINNT\WindowsUpdate.log Object is locked skipped

Scan process completed.

jeremyb
2008-05-06, 15:48
New HJT log..... (also the system seems to be running ok... the only thing odd is when the first url you try to visit when you open a browser seems to take a while when logged in as this user)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:43, on 2008-05-06
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINNT\system32\svchost.exe
C:\ePOAgent\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\explorer.exe
C:\Documents and Settings\FAYSHE\Desktop\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINNT\system32\keyhook.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\ePOAgent\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [INACASAP] C:\Program Files\INAC\Anti Spyware\inac2.exe /h
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hartson-kennedy.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{CBAF6C6B-4DD6-4082-8F1D-09923D092AE0}: NameServer = 204.242.1.21,204.242.1.24
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hartson-kennedy.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hartson-kennedy.com
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\ePOAgent\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - McAfee, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe

--
End of file - 4098 bytes

Blade81
2008-05-06, 16:31
Hi


Show hidden files
-----------------
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

Delete following file if found:
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Targetsaver.zip


Delete also items in C:\quarantine folder (don't delete the folder itself!).



Create & execute batch file
-------------------------------

Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file MoveFiles.bat, change the Save as type to all files and save it to your desktop. (If you are still unsure on how to do this there is a little tutorial with pictures here (http://www.nellie2.co.uk/file.htm#How_to_Make_a_.Bat_File))

move /Y C:\ePOAgent\bak\UpdaterUI.exe C:\ePOAgent
move /Y C:\WINNT\system32\bak\keyhook.exe C:\WINNT\system32
move /Y C:\WINNT\system32\bak\sistray.EXE C:\WINNT\system32



Double-click on MoveFiles.bat file to execute it. You may delete the bat file after it has been executed.



the only thing odd is when the first url you try to visit when you open a browser seems to take a while when logged in as this user
This might be because of cleaning browser cache and other temporary items with ATF Cleaner earlier.

jeremyb
2008-05-12, 21:07
Thank you so much for your help... it was really appreciated!!! All is good again.

Jeremy

Blade81
2008-05-12, 21:14
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help. :)

Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.