Lurker87
2010-07-15, 04:30
I am trying to help a friend whose Vista Business 32-bit computer has recently started showing quite a few symptoms of malware. I ran Malwarebyte, and was able to get rid of about ten infections, however some were unable to be removed. However, there were still instances of the browser being hijacked, often to sites such as 7search.com, and others. I went on to use HJT to look for other malware possibilities, and this was when I first came across the problem of "For some reason your system denied write access to the Hosts file... etc". I have googled both it and the wininit version of the error message.
I took a look at the log and noticed the list of 'hosts' appeared quite substantial.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:10:23 PM, on 7/14/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 188.124.7.188 www.google.com
O1 - Hosts: 188.124.7.188 google.com
O1 - Hosts: 188.124.7.188 google.com.au
O1 - Hosts: 188.124.7.188 www.google.com.au
O1 - Hosts: 188.124.7.188 google.be
O1 - Hosts: 188.124.7.188 www.google.be
O1 - Hosts: 188.124.7.188 google.com.br
O1 - Hosts: 188.124.7.188 www.google.com.br
O1 - Hosts: 188.124.7.188 google.ca
O1 - Hosts: 188.124.7.188 www.google.ca
O1 - Hosts: 188.124.7.188 google.ch
O1 - Hosts: 188.124.7.188 www.google.ch
O1 - Hosts: 188.124.7.188 google.de
O1 - Hosts: 188.124.7.188 www.google.de
O1 - Hosts: 188.124.7.188 google.dk
O1 - Hosts: 188.124.7.188 www.google.dk
O1 - Hosts: 188.124.7.188 google.fr
O1 - Hosts: 188.124.7.188 www.google.fr
O1 - Hosts: 188.124.7.188 google.ie
O1 - Hosts: 188.124.7.188 www.google.ie
O1 - Hosts: 188.124.7.188 google.it
O1 - Hosts: 188.124.7.188 www.google.it
O1 - Hosts: 188.124.7.188 google.co.jp
O1 - Hosts: 188.124.7.188 www.google.co.jp
O1 - Hosts: 188.124.7.188 google.nl
O1 - Hosts: 188.124.7.188 www.google.nl
O1 - Hosts: 188.124.7.188 google.no
O1 - Hosts: 188.124.7.188 www.google.no
O1 - Hosts: 188.124.7.188 google.co.nz
O1 - Hosts: 188.124.7.188 www.google.co.nz
O1 - Hosts: 188.124.7.188 google.pl
O1 - Hosts: 188.124.7.188 www.google.pl
O1 - Hosts: 188.124.7.188 google.se
O1 - Hosts: 188.124.7.188 www.google.se
O1 - Hosts: 188.124.7.188 google.co.uk
O1 - Hosts: 188.124.7.188 www.google.co.uk
O1 - Hosts: 188.124.7.188 google.co.za
O1 - Hosts: 188.124.7.188 www.google.co.za
O1 - Hosts: 188.124.7.188 www.google-analytics.com
O1 - Hosts: 188.124.7.188 www.bing.com
O1 - Hosts: 188.124.7.188 search.yahoo.com
O1 - Hosts: 188.124.7.188 www.search.yahoo.com
O1 - Hosts: 188.124.7.188 uk.search.yahoo.com
O1 - Hosts: 188.124.7.188 ca.search.yahoo.com
O1 - Hosts: 188.124.7.188 de.search.yahoo.com
O1 - Hosts: 188.124.7.188 fr.search.yahoo.com
O1 - Hosts: 188.124.7.188 au.search.yahoo.com
O2 - BHO: C:\Windows\system32\ar8315.dll - {A3BA40A2-74F0-42BD-F434-00B15A2C8953} - C:\Windows\system32\ar8315.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Remote System Protection] rundll32.exe C:\Windows\system32\ar8315.dll, HUI_proc
O15 - Trusted Zone: http://*.buy-security-essentials.com
O15 - Trusted Zone: http://*.download-soft-package.com
O15 - Trusted Zone: http://*.download-software-package.com
O15 - Trusted Zone: http://*.get-key-se10.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.buy-security-essentials.com (HKLM)
O15 - Trusted Zone: http://*.get-key-se10.com (HKLM)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O20 - Winlogon Notify: zzop93 - zzop93.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: 7whfiudhf8s7f3oifhif7syfdhsof - {A3BA40A2-74F0-42BD-F434-00B15A2C8953} - C:\Windows\system32\ar8315.dll
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
------------------------------------------------------------------
I googled multiple techniques to get around this, and have tried other removal methods, such as adaware S&D, and even going so far as to try using ComboFix, which only made it to stage 5 after an hour, before I finally canceled it and began searching again. I have come across the hosts file in Windows/System32/driver/etc, and have tried multiple variations of granting permissions, as well as ownership, to both it and spybot, and each time, I obtained an error that mentioned the hosts file or wininit. I came across HostsXpert in one of this site's threads as a possible way to unlock the hosts file, but upon trying to restore MS's hosts file, I obtained the error "ERROR: Cannot create file C:\Windows\System32\DRIVERS\ETC\hosts"... no surprise there X(
I have deactivated all the antivirus programs (I believe), and have disconnected from the internet, as well as all pages and email clients. The firewall is down, and now I'm running out of ideas. However, I am basing this on the conclusion that I need to find some way to allow access to the hosts and wininit files.
I am still finding multiple malware infections, and would appreciate any help. After 7 hours of stumbling around, I have only succeeded in further proving my ignorance :sad:
----------------------------------
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)
I took a look at the log and noticed the list of 'hosts' appeared quite substantial.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:10:23 PM, on 7/14/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18294)
Boot mode: Safe mode
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 188.124.7.188 www.google.com
O1 - Hosts: 188.124.7.188 google.com
O1 - Hosts: 188.124.7.188 google.com.au
O1 - Hosts: 188.124.7.188 www.google.com.au
O1 - Hosts: 188.124.7.188 google.be
O1 - Hosts: 188.124.7.188 www.google.be
O1 - Hosts: 188.124.7.188 google.com.br
O1 - Hosts: 188.124.7.188 www.google.com.br
O1 - Hosts: 188.124.7.188 google.ca
O1 - Hosts: 188.124.7.188 www.google.ca
O1 - Hosts: 188.124.7.188 google.ch
O1 - Hosts: 188.124.7.188 www.google.ch
O1 - Hosts: 188.124.7.188 google.de
O1 - Hosts: 188.124.7.188 www.google.de
O1 - Hosts: 188.124.7.188 google.dk
O1 - Hosts: 188.124.7.188 www.google.dk
O1 - Hosts: 188.124.7.188 google.fr
O1 - Hosts: 188.124.7.188 www.google.fr
O1 - Hosts: 188.124.7.188 google.ie
O1 - Hosts: 188.124.7.188 www.google.ie
O1 - Hosts: 188.124.7.188 google.it
O1 - Hosts: 188.124.7.188 www.google.it
O1 - Hosts: 188.124.7.188 google.co.jp
O1 - Hosts: 188.124.7.188 www.google.co.jp
O1 - Hosts: 188.124.7.188 google.nl
O1 - Hosts: 188.124.7.188 www.google.nl
O1 - Hosts: 188.124.7.188 google.no
O1 - Hosts: 188.124.7.188 www.google.no
O1 - Hosts: 188.124.7.188 google.co.nz
O1 - Hosts: 188.124.7.188 www.google.co.nz
O1 - Hosts: 188.124.7.188 google.pl
O1 - Hosts: 188.124.7.188 www.google.pl
O1 - Hosts: 188.124.7.188 google.se
O1 - Hosts: 188.124.7.188 www.google.se
O1 - Hosts: 188.124.7.188 google.co.uk
O1 - Hosts: 188.124.7.188 www.google.co.uk
O1 - Hosts: 188.124.7.188 google.co.za
O1 - Hosts: 188.124.7.188 www.google.co.za
O1 - Hosts: 188.124.7.188 www.google-analytics.com
O1 - Hosts: 188.124.7.188 www.bing.com
O1 - Hosts: 188.124.7.188 search.yahoo.com
O1 - Hosts: 188.124.7.188 www.search.yahoo.com
O1 - Hosts: 188.124.7.188 uk.search.yahoo.com
O1 - Hosts: 188.124.7.188 ca.search.yahoo.com
O1 - Hosts: 188.124.7.188 de.search.yahoo.com
O1 - Hosts: 188.124.7.188 fr.search.yahoo.com
O1 - Hosts: 188.124.7.188 au.search.yahoo.com
O2 - BHO: C:\Windows\system32\ar8315.dll - {A3BA40A2-74F0-42BD-F434-00B15A2C8953} - C:\Windows\system32\ar8315.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Remote System Protection] rundll32.exe C:\Windows\system32\ar8315.dll, HUI_proc
O15 - Trusted Zone: http://*.buy-security-essentials.com
O15 - Trusted Zone: http://*.download-soft-package.com
O15 - Trusted Zone: http://*.download-software-package.com
O15 - Trusted Zone: http://*.get-key-se10.com
O15 - Trusted Zone: http://*.is-software-download.com
O15 - Trusted Zone: http://*.buy-security-essentials.com (HKLM)
O15 - Trusted Zone: http://*.get-key-se10.com (HKLM)
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O20 - Winlogon Notify: zzop93 - zzop93.dll (file missing)
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: 7whfiudhf8s7f3oifhif7syfdhsof - {A3BA40A2-74F0-42BD-F434-00B15A2C8953} - C:\Windows\system32\ar8315.dll
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: PEVSystemStart - Unknown owner - C:\ComboFix\PEV.cfxxe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
------------------------------------------------------------------
I googled multiple techniques to get around this, and have tried other removal methods, such as adaware S&D, and even going so far as to try using ComboFix, which only made it to stage 5 after an hour, before I finally canceled it and began searching again. I have come across the hosts file in Windows/System32/driver/etc, and have tried multiple variations of granting permissions, as well as ownership, to both it and spybot, and each time, I obtained an error that mentioned the hosts file or wininit. I came across HostsXpert in one of this site's threads as a possible way to unlock the hosts file, but upon trying to restore MS's hosts file, I obtained the error "ERROR: Cannot create file C:\Windows\System32\DRIVERS\ETC\hosts"... no surprise there X(
I have deactivated all the antivirus programs (I believe), and have disconnected from the internet, as well as all pages and email clients. The firewall is down, and now I'm running out of ideas. However, I am basing this on the conclusion that I need to find some way to allow access to the hosts and wininit files.
I am still finding multiple malware infections, and would appreciate any help. After 7 hours of stumbling around, I have only succeeded in further proving my ignorance :sad:
----------------------------------
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)