PDA

View Full Version : Malware or System File(s) Corruption?



TomPabst
2006-06-02, 06:49
Hi Guys and Gals.....

I almost posted this problem in the SpyBot forum as the symptoms of this malware (or system file corruption) first showed up with a malfunction in the SpyBot scan I did last Monday morning (after downloading the latest "includeds" of 5/26). I had very little desk time left Monday so I decided to wait until I could do more checks before posting that there was a problem with the "includes 5/26/2006" download. I had no office time on Tuesday and very little on Wednesday, so this is why I'm just getting to making this post tonight (Thursday night, 6/1/06). But I've now had the last several hours to check out this infection....it's a bizarre one (at least with my experience level to date).

Here are the symptoms and I will begin with last Monday morning (5/29) problem with the SpyBot scan:

(1) 5/29/06: Downloaded latest "includes" from SpyBot Updates and installed (no issues). Ran scan immediately (after system reboot) and got the following error message (red triangle with exclamation point in center on SB scan page): "Services.sbs file missing, go to updates to replace it." (Not verbatim, but close enough). I downloaded the "5/26 includes" again (by xx-rename the "downloaded.ini" file in the SB "Updates" folder), and reinstalled them. Result: Same error message upon running SB scan. I also tried extracting the "services.sbs" file manually from the "includes.zip" file.....it will not extract (but all other files in the zip will extract to a temp folder pointed to). And probably don't need to say this, but indeed, "services.sbs" file is not located in the SB Includes folder. The last good SB scan I ran was on Saturday, 5/27 and nothing unusual was detected (some tracking cookies and that was it). I've not been able to run a good SB scan since then.

(2) Today: I ran HJT scan and compared to last Sunday's HJT scan. They were identical (and both are the same as the one I've posted below) with one "odd man out" entry at F2 (see below). I checked the last HJT routine scan I have archived (I run HJT about 3 to 6 times per week as routine, and just archive those scans dated/timed)....which was on Friday, 5/26 and the "F2" entry was not present. Please note: The HJT scan below says that "processes can not be listed." That also appears on the previous scans except for last Friday when the F2 is not present.

(3) Went to the "target file" of the F2 regentry, "services.exe" and tried to rename it. Can't, says "File is in use by another program." Also tried to delete it. Can't, says "Disk is full....yada, yada, yada." Neither was a surprise but I always like to try it! -:)

Now it starts getting weird!

(4) Following standard procedures before posting in this Malware Forum, I ran my eTrust AV program (on C drive only). It runs about 1/3 through the "Documents and Settings" folder and then hangs with: "ETrust AV has encountered a problem and needs to close....yada, yada, yada." App hangs and needs to be control/alt/deleted to "end program" and clear.

(5) Attempted to look for a "services.dll" file in Windows/system32 folder and this blows me away: I can't access the folder. As soon as I click on it, I get a message such as, "Windows Explorer has encountered a problem and needs to close!" Nervously I decided to go to "system restore".......

(6) Can't open System Restore! Message says, "System Restore can not protect your computer, please reboot and try again." Now I'm thinking my WinXP, SP2 ops sys is in big trouble.

(7) Made several attempts to let HJT "fix" the F2 entry....it removes it but it's back after either a reboot and HJT rerun, or a HJT rerun without rebooting.

(8) Finally was able to access the c:windows/system32 folder by doing the following: Change the "View" from "list/details" to "thumbnails" and I could open the system32 folder. I immediately looked for a "services.dll" file (just for grins) but none existed. I went to the "restore" folder and almost fell out of my chair! Something had "xx-renamed" the "filelist.xml" file to "xxfilelist.xml".......huh? I renamed it back. Opened "System Restore" from the normal "start/programs/help" and it started right up. I was delighted....but it didn't last long! All the "restore points" prior to today's date have been deleted.

And that leads me to making this post. I'm not screwing with this buggar any more as you guys are the experts. I'm hoping this is not something new? But I'm fearful that it might be. Other than email and IE browser (which work fine or seemed to work fine), I've not tried running any other programs.

My HJT log follows (minus the "running processes" list as indicated:
(Note: Every entry on this HJT log is known to be good to me, except the F2 entry.)

Logfile of HijackThis v1.99.1
Scan saved at 6:43:48 PM, on 6/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

(Unable to list running processes)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,,C:\WINDOWS\SERVICES.EXE
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo30\MemTurbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Color'n'Code Wizzard.lnk = C:\Program Files\Color n Code\Common\IconMgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135272627828
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

*************end HJT Log******************

Besides fixing this nasty thing.....I'd be interested to know what purpose it was written to do.....other than screwing up my computer. It seems particularly malicious for some reason to me?

Lonny....you da man! Have at it! -:)

Regards,

Tom Pabst

LonnyRJones
2006-06-03, 07:24
Post a report from this tool if any FILES show
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
Click the i accept button near the bottom of that page.
Download and run blacklite click > scan then > next, next again then exit
there will be a new txt near blacklite. post it please.
Important: If any files show Do not rename them YET.....legitimate files can be listed.

TomPabst
2006-06-03, 09:09
Lonny.....

"Blacklight".....that's a trick little piece of software!

Here's the BL Log:

06/02/06 23:55:21 [Info]: BlackLight Engine 1.0.37 initialized
06/02/06 23:55:21 [Info]: OS: 5.1 build 2600 (Service Pack 2)
06/02/06 23:55:21 [Note]: 7019 4
06/02/06 23:55:21 [Note]: 7005 0
06/02/06 23:55:38 [Note]: 7006 0
06/02/06 23:55:38 [Note]: 7011 1872
06/02/06 23:55:38 [Note]: 7026 0
06/02/06 23:55:38 [Note]: 7026 0
06/02/06 23:55:38 [Note]: 7024 3
06/02/06 23:55:38 [Info]: Hidden process: C:\WINDOWS\system32\svchost.exe
06/02/06 23:55:38 [Note]: 7024 3
06/02/06 23:55:38 [Info]: Hidden process: C:\WINDOWS\System32\svchost.exe
06/02/06 23:55:38 [Note]: 7024 3
06/02/06 23:55:38 [Info]: Hidden process: C:\WINDOWS\system32\svchost.exe
06/02/06 23:55:38 [Note]: 7024 3
06/02/06 23:55:38 [Info]: Hidden process: C:\WINDOWS\system32\svchost.exe
06/02/06 23:55:38 [Note]: 7024 3
06/02/06 23:55:38 [Info]: Hidden process: C:\WINDOWS\system32\svchost.exe
06/02/06 23:55:38 [Note]: FSRAW library version 1.7.1015
06/02/06 23:56:01 [Info]: Hidden file: c:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.
06/02/06 23:56:01 [Note]: 10002 1
06/02/06 23:56:07 [Info]: Hidden file: c:\Documents and Settings\Bob Davis\Local Settings\Temp\Services.sbs
06/02/06 23:56:07 [Note]: 10002 1
06/02/06 23:56:57 [Info]: Hidden file: c:\Documents and Settings\Bob Davis\My Documents\Temp-Zip\Services.sbs
06/02/06 23:56:57 [Note]: 10002 1
06/02/06 23:57:22 [Info]: Hidden file: c:\Program Files\Common Files\Services\bigfoot.bmp
06/02/06 23:57:22 [Note]: 10002 3
06/02/06 23:57:22 [Info]: Hidden file: c:\Program Files\Common Files\Services\verisign.bmp
06/02/06 23:57:22 [Note]: 10002 3
06/02/06 23:57:22 [Info]: Hidden file: c:\Program Files\Common Files\Services\whowhere.bmp
06/02/06 23:57:22 [Note]: 10002 3
06/02/06 23:57:47 [Info]: Hidden file: c:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
06/02/06 23:57:47 [Note]: 10002 1
06/02/06 23:58:00 [Info]: Hidden file: c:\WINDOWS\system32\dllcache\services.exe
06/02/06 23:58:00 [Note]: 10002 1
06/02/06 23:58:01 [Info]: Hidden file: c:\WINDOWS\system32\drivers\etc\services
06/02/06 23:58:01 [Note]: 10002 1
06/02/06 23:58:03 [Info]: Hidden file: c:\WINDOWS\system32\services.exe
06/02/06 23:58:03 [Note]: 10002 1
06/02/06 23:58:04 [Info]: Hidden file: c:\WINDOWS\system32\services.msc
06/02/06 23:58:04 [Note]: 10002 1
06/02/06 23:58:06 [Info]: Hidden file: c:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\5.8.0.2469\wups
06/02/06 23:58:06 [Note]: 10002 3
06/02/06 23:58:10 [Info]: Hidden file: c:\WINDOWS\services.dll
06/02/06 23:58:10 [Note]: 10002 1
06/02/06 23:58:11 [Info]: Hidden file: c:\WINDOWS\SERVICES.EXE
06/02/06 23:58:11 [Note]: 7002 0
06/02/06 23:58:11 [Note]: 7003 1
06/02/06 23:58:11 [Note]: 10002 1
06/02/06 23:58:11 [Info]: Hidden file: c:\WINDOWS\services32.dll
06/02/06 23:58:11 [Note]: 7002 0
06/02/06 23:58:11 [Note]: 7003 1
06/02/06 23:58:11 [Note]: 10002 1
06/02/06 23:58:34 [Info]: Hidden file: e:\My Documents-old_Win98se\My Webs\_vti_pvt\services.cnf
06/02/06 23:58:34 [Note]: 10002 1
06/03/06 00:02:17 [Note]: 7007 0

***********end BlackLight Log****************

Standing by for further instructs.

Regards,

Tom

LonnyRJones
2006-06-03, 09:32
Thanks

Run blacklite again and have it rename ONLY
c:\WINDOWS\services.dll
c:\WINDOWS\SERVICES.EXE
c:\WINDOWS\services32.dll
let blacklite restart your pc
make another hijackthis and blacklite logs and post them please.

TomPabst
2006-06-03, 20:12
Lonny...

Thanks for your help on this by the way.

New HJT and Blacklight logs copied below as per your instructions. But, first a couple questions and comments:

(1) Question: Do you guys know what "malware" (by name) program this is? Is it a known....or is it something new? Just curious.....

(2) Comment: The Blacklight "step 2 Clean" process only lists files it found, it does not show them in their pathway. Your instructions to "rename" includes a pathway....but does not indicate whether the file names you list are "case senstive" names. This was confusing to me. For example: There were several instances of "services.exe" but I only deleted the ones exactly as you listed (without a pathway, I could not tell which to delete when more than once instance of a file was on the Blacklight list). I very easily could have taken your instructions to mean: Delete all instances....of those three file names. I didn't do it.....but only because I wanted to be conservative at this point (I figured I could always go back and delete the others if I interpreted your instructions incorrectly). Suggest you be clearer about this perhaps, in the future. Just a helpful suggestion.

***********Blacklight Log******************
06/03/06 10:54:29 [Info]: BlackLight Engine 1.0.37 initialized
06/03/06 10:54:29 [Info]: OS: 5.1 build 2600 (Service Pack 2)
06/03/06 10:54:29 [Note]: 7019 4
06/03/06 10:54:29 [Note]: 7005 0
06/03/06 10:54:31 [Note]: 7006 0
06/03/06 10:54:31 [Note]: 7011 1256
06/03/06 10:54:31 [Note]: 7026 0
06/03/06 10:54:31 [Note]: 7026 0
06/03/06 10:54:36 [Note]: FSRAW library version 1.7.1015
06/03/06 10:56:31 [Note]: 7007 0
***********End Blacklight Log****************

***********HJT Log***********************
Logfile of HijackThis v1.99.1
Scan saved at 10:58:38 AM, on 6/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\WS_FTP Pro\ftpsched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Color n Code\Common\IconMgr.exe
C:\Program Files\MemTurbo30\MemTurbo.exe
C:\Program Files\Color n Code\ColorWizzard\hgcctl95.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\SpyWare Tools\HiJackThis_Ops\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,,C:\WINDOWS\SERVICES.EXE
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo30\MemTurbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Color'n'Code Wizzard.lnk = C:\Program Files\Color n Code\Common\IconMgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135272627828
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
**************End HJT Log**********************

I am not going to be at my computer again today until some time around 9pm (PacificDaylight Time) tonight. Will follow up with further instructions from you at that time.

Regards,

Tom

LonnyRJones
2006-06-03, 20:32
Fix this item using Hiajvkthis
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,,C:\WINDOWS\SERVICES.EXE

Go here and submit these files
http://www.virustotal.com/flash/index_en.html
c:\WINDOWS\services.dll.ren
c:\WINDOWS\SERVICES.EXE.ren
c:\WINDOWS\services32.dll.ren
Post back with what is found

Good point about blacklite not showing paths when at the area to rename

TomPabst
2006-06-04, 12:06
Lonny,

Should I submit those files via email (so I get a report back)....or do they report back even when submitting directly? Also, do I need to remove the ".ren" we added to the end of them?

Please advise,

Tom

TomPabst
2006-06-05, 17:17
Lonny,

Figured out how to use the Virustotal site.....here's the scan results of all three files:

STATUS: FINISHEDComplete scanning result of "services32.dll.ren", received in VirusTotal at 06.05.2006, 16:41:32 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.37 06.05.2006 no virus found
Authentium 4.93.8 06.02.2006 no virus found
Avast 4.7.844.0 06.05.2006 no virus found
AVG 386 06.02.2006 Generic.UXX
BitDefender 7.2 06.05.2006 Trojan.Downloader.Agent.VY
CAT-QuickHeal 8.00 06.05.2006 no virus found
ClamAV devel-20060426 06.04.2006 no virus found
DrWeb 4.33 06.05.2006 DLOADER.Trojan
eTrust-InoculateIT 23.72.28 06.04.2006 no virus found
eTrust-Vet 12.6.2243 06.05.2006 no virus found
Ewido 3.5 06.05.2006 Downloader.Agent.zf
Fortinet 2.77.0.0 06.05.2006 no virus found
F-Prot 3.16f 06.02.2006 no virus found
Ikarus 0.2.65.0 06.02.2006 no virus found
Kaspersky 4.0.2.24 06.05.2006 Trojan-Downloader.Win32.Agent.zf
McAfee 4776 06.02.2006 Generic Downloader.ab
Microsoft 1.1441 06.05.2006 no virus found
NOD32v2 1.1579 06.05.2006 no virus found
Norman 5.90.17 06.05.2006 no virus found
Panda 9.0.0.4 06.04.2006 Trj/Downloader.IWZ
Sophos 4.05.0 06.05.2006 no virus found
Symantec 8.0 06.05.2006 no virus found
TheHacker 5.9.8.155 06.05.2006 Trojan/Downloader.Agent.zf
UNA 1.83 06.02.2006 no virus found
VBA32 3.11.0 06.05.2006 suspected of Downloader.Small.189


Aditional Information
File size: 10752 bytes
MD5: 864d2b59f5025708513cc46bdbe54fb1
SHA1: d2b2c78d88831adb69e6be739ca66e8cf5862cd1

*****************************************************************************************

STATUS: FINISHEDComplete scanning result of "services.dll.ren", received in VirusTotal at 06.05.2006, 16:55:30 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.37 06.05.2006 no virus found
Authentium 4.93.8 06.02.2006 no virus found
Avast 4.7.844.0 06.05.2006 no virus found
AVG 386 06.02.2006 Downloader.Generic2.AJX
BitDefender 7.2 06.05.2006 Trojan.Agent.Hook.A
CAT-QuickHeal 8.00 06.05.2006 no virus found
ClamAV devel-20060426 06.04.2006 no virus found
DrWeb 4.33 06.05.2006 no virus found
eTrust-InoculateIT 23.72.28 06.04.2006 no virus found
eTrust-Vet 12.6.2243 06.05.2006 no virus found
Ewido 3.5 06.05.2006 no virus found
Fortinet 2.77.0.0 06.05.2006 no virus found
F-Prot 3.16f 06.02.2006 no virus found
Ikarus 0.2.65.0 06.02.2006 no virus found
Kaspersky 4.0.2.24 06.05.2006 no virus found
McAfee 4776 06.02.2006 Generic Downloader.ab
Microsoft 1.1441 06.05.2006 no virus found
NOD32v2 1.1579 06.05.2006 no virus found
Norman 5.90.17 06.05.2006 no virus found
Panda 9.0.0.4 06.04.2006 Trj/Downloader.IWZ
Sophos 4.05.0 06.05.2006 no virus found
Symantec 8.0 06.05.2006 no virus found
TheHacker 5.9.8.155 06.05.2006 no virus found
UNA 1.83 06.02.2006 no virus found
VBA32 3.11.0 06.05.2006 no virus found


Aditional Information
File size: 3584 bytes
MD5: d3bae1381a6a20b292f54ea94b347f23
SHA1: 5a6dcdb3de01426e53b4068f628fd1a40e5be206

********************************************************************************************

STATUS: FINISHEDComplete scanning result of "SERVICES.EXE.ren", received in VirusTotal at 06.05.2006, 17:04:11 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.37 06.05.2006 TR/Dldr.Agent.16422
Authentium 4.93.8 06.02.2006 could be infected with an unknown virus
Avast 4.7.844.0 06.05.2006 no virus found
AVG 386 06.05.2006 Generic.UXW
BitDefender 7.2 06.05.2006 Trojan.Downloader.Agent.VY
CAT-QuickHeal 8.00 06.05.2006 (Suspicious) - DNAScan
ClamAV devel-20060426 06.04.2006 no virus found
DrWeb 4.33 06.05.2006 Trojan.Serenta
eTrust-InoculateIT 23.72.28 06.04.2006 no virus found
eTrust-Vet 12.6.2243 06.05.2006 no virus found
Ewido 3.5 06.05.2006 Downloader.Agent.zf
Fortinet 2.77.0.0 06.05.2006 suspicious
F-Prot 3.16f 06.02.2006 could be infected with an unknown virus
Ikarus 0.2.65.0 06.02.2006 Trojan-Downloader.Win32.Harnig.bl
Kaspersky 4.0.2.24 06.05.2006 Trojan-Downloader.Win32.Agent.zf
McAfee 4776 06.02.2006 no virus found
Microsoft 1.1441 06.05.2006 no virus found
NOD32v2 1.1579 06.05.2006 no virus found
Norman 5.90.17 06.05.2006 W32/Agent.ABWD
Panda 9.0.0.4 06.04.2006 Trj/Downloader.IWZ
Sophos 4.05.0 06.05.2006 no virus found
Symantec 8.0 06.05.2006 no virus found
TheHacker 5.9.8.155 06.05.2006 no virus found
UNA 1.83 06.02.2006 TrojanDownloader.Win32.Agent
VBA32 3.11.0 06.05.2006 Trojan-Downloader.Win32.Agent.zf


Aditional Information
File size: 16422 bytes
MD5: c2dc983af2e40af25d6ea7c6152cf775
SHA1: dd70c4b305247c4949a9a1c201e6612a4eb20428
Packers: FSG

*******************end virus ID scan report*************

I'm going to run another HJT report and post it below.....just for an "all clear" report from you.

Regards,

Tom

TomPabst
2006-06-05, 17:30
Lonny,

Here's an HJT report run just a few minutes ago. Looks "all clear" to me. How about you?

Regards,

Tom

PS: Can I place "ignore checks" on all of these so it makes it easier to pick out something "new" and suspicious that may be added by malware?

TomPabst
2006-06-05, 17:30
Oooops...forgot to copy the HJT log. Here you go..........

Logfile of HijackThis v1.99.1
Scan saved at 8:27:57 AM, on 6/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\WS_FTP Pro\ftpsched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Color n Code\Common\IconMgr.exe
C:\Program Files\Color n Code\ColorWizzard\hgcctl95.exe
C:\Program Files\MemTurbo30\MemTurbo.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\SpyWare Tools\HiJackThis_Ops\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/home.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [TClockEx] C:\Program Files\TClockEx\TCLOCKEX.EXE
O4 - Startup: MemTurbo.lnk = C:\Program Files\MemTurbo30\MemTurbo.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Color'n'Code Wizzard.lnk = C:\Program Files\Color n Code\Common\IconMgr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_44.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135272627828
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Autodesk Licensing Service - Unknown owner - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Ipswitch WS_FTP Queue (ftpqueue) - Ipswitch, Inc., 81 Hartwell Ave, Lexington MA 02421 - C:\Program Files\WS_FTP Pro\ftpsched.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

LonnyRJones
2006-06-05, 17:34
If you havent deleted them yet send them to etrust.
I cant find there submit email, perhaps you can from inside the program.
Then the files can be deleted.

I dont see a hjt log :)

Yes for your own viewing you can use HJT ignorelist, but when posting it in forums alwys delete the ignorlist first.

LonnyRJones
2006-06-05, 17:35
Looks fine

TomPabst
2006-06-06, 06:54
Lonny,

I submitted all three files to ETrust this evening. Their "virus submit" forms are now inside their "USER ID Log-in" so perhaps that is why you didn't keep their "submit URL" any longer?

Thought this malware/trojan was very effective in preventing normal removal (deactivation of System Restore was something I'd never heard of before), I still don't know what true "payload" this thing was intended for as it would periodically cause IE to autolaunch....only to attempt connecting to a dead URL (somewhere in Italy). Perhaps that was all it was supposed to do and the true "payload" files would be downloaded from that site?

I suppose this is the end of this "event." This string can be removed. As always, your help is sincerely appreciated.

Until we meet again..... -:)

Regards,

Tom

LonnyRJones
2006-06-06, 14:43
If you havent already disable system restore, reboot and enable it again.

Surf safe

tashi
2006-06-11, 09:12
As the problem appears to be resolved this topic will be archived. :bigthumb:

If you need it re-opened please send me a pm and provide a link to the thread.