BloodyPeasant
2008-07-11, 02:45
Yesterday. Ad-Watch notified me of a change to appinit.dll involving nvdesk... don't recall the name exactly.
Ran Ad-Aware and tried to run S&D but it wouldn't come up.
Looked in the forums here and was able to download a new exe on a different computer and renamed it on the affected box and was able to run it.
After fixing the problems, wnspoem and ntos, rebooted into safe mode and ran S&D again.
Wnspoem reported present, and hjt sees the braviax and cru629.
This is a very old box and if it's easier to nuke it and reinstall that wouldn't be the end of the world, just a pita to reinstall the programs I use on it which are mainly streaming radio.
I'm using a flash drive to move files back and forth as I disconnected the infected box from my home network.
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:22:13, on 07/10/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\taskmgr.exe
C:\Spybot - Search & Destroy\SotSD.exe
D:\hijack\This.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\ntos.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SM1BG] C:\WINNT\SM1BG.EXE
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [braviax] braviax.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA7121] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3497] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9428] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC226] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Spybot - Search & Destroy\SotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA4121] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1100] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8608] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC224] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7159] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6526] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3875] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC968] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB615] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD404] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8427] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6353] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4084] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6753] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB120] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6755] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3793] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2185] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4496] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3075] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371050.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.ritzpix.com/upload/FujifilmUploadClient.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup155.cab
O20 - AppInit_DLLs: C:\WINNT\system32\cru629.dat
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
--
End of file - 8023 bytes
Thanks for taking a look.
Ran Ad-Aware and tried to run S&D but it wouldn't come up.
Looked in the forums here and was able to download a new exe on a different computer and renamed it on the affected box and was able to run it.
After fixing the problems, wnspoem and ntos, rebooted into safe mode and ran S&D again.
Wnspoem reported present, and hjt sees the braviax and cru629.
This is a very old box and if it's easier to nuke it and reinstall that wouldn't be the end of the world, just a pita to reinstall the programs I use on it which are mainly streaming radio.
I'm using a flash drive to move files back and forth as I disconnected the infected box from my home network.
HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:22:13, on 07/10/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Safe mode with network support
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\taskmgr.exe
C:\Spybot - Search & Destroy\SotSD.exe
D:\hijack\This.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\ntos.exe,
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SM1BG] C:\WINNT\SM1BG.EXE
O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKLM\..\Run: [braviax] braviax.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA7121] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3497] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9428] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC226] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Spybot - Search & Destroy\SotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA4121] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC1100] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8608] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC224] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA7159] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6526] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3875] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC968] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB615] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD404] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8427] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6353] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4084] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6753] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB120] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6755] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3793] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2185] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4496] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3075] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/ICSScanner371050.cab
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/promotions/spywaredetector/WebSWK.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.ritzpix.com/upload/FujifilmUploadClient.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup155.cab
O20 - AppInit_DLLs: C:\WINNT\system32\cru629.dat
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe
--
End of file - 8023 bytes
Thanks for taking a look.