Results 1 to 7 of 7

Thread: Braviax, cru629, wsnpoem

  1. #1
    Junior Member BloodyPeasant's Avatar
    Join Date
    Jul 2008
    Posts
    3

    Default Braviax, cru629, wsnpoem

    Yesterday. Ad-Watch notified me of a change to appinit.dll involving nvdesk... don't recall the name exactly.
    Ran Ad-Aware and tried to run S&D but it wouldn't come up.
    Looked in the forums here and was able to download a new exe on a different computer and renamed it on the affected box and was able to run it.
    After fixing the problems, wnspoem and ntos, rebooted into safe mode and ran S&D again.
    Wnspoem reported present, and hjt sees the braviax and cru629.
    This is a very old box and if it's easier to nuke it and reinstall that wouldn't be the end of the world, just a pita to reinstall the programs I use on it which are mainly streaming radio.
    I'm using a flash drive to move files back and forth as I disconnected the infected box from my home network.

    HJT log:
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:22:13, on 07/10/2008
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Safe mode with network support

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\csrss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\system32\taskmgr.exe
    C:\Spybot - Search & Destroy\SotSD.exe
    D:\hijack\This.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
    F2 - REG:system.ini: UserInit=C:\WINNT\system32\userinit.exe,C:\WINNT\system32\ntos.exe,
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\YAHOO!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [SM1BG] C:\WINNT\SM1BG.EXE
    O4 - HKLM\..\Run: [TotalRecorderScheduler] "C:\Program Files\HighCriteria\TotalRecorder\TotRecSched.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINNT\system32\ezSP_Px.exe
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
    O4 - HKLM\..\Run: [braviax] braviax.exe
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7121] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC3497] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA9428] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC226] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Spybot - Search & Destroy\SotSD.exe" /autocheck
    O4 - HKLM\..\RunOnce: [SpybotDeletingA4121] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC1100] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA8608] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC224] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA7159] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC6526] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingA3875] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKLM\..\RunOnce: [SpybotDeletingC968] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKCU\..\Run: [AWMON] "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Watch.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\RunOnce: [SpybotDeletingB615] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD404] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB8427] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6353] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4084] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6753] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB120] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD6755] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB3793] command /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD2185] cmd /c del "C:\WINNT\system32\wsnpoem\audio.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingB4496] command /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKCU\..\RunOnce: [SpybotDeletingD3075] cmd /c del "C:\WINNT\system32\wsnpoem\video.dll"
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
    O16 - DPF: Yahoo! Blackjack - http://download2.games.yahoo.com/gam...ts/y/jt0_x.cab
    O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/game...ts/y/it1_x.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/pro...nner371050.cab
    O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller Class) - http://download.zonelabs.com/bin/pro...tor/WebSWK.cab
    O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.ritzpix.com/upload/FujifilmUploadClient.cab
    O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download...basetup155.cab
    O20 - AppInit_DLLs: C:\WINNT\system32\cru629.dat
    O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
    O23 - Service: TiVo Beacon (TivoBeacon2) - TiVo Inc. - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe

    --
    End of file - 8023 bytes

    Thanks for taking a look.

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi BloodyPeasant

    One or more of the identified infections is a backdoor trojan.

    This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

    I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

    Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

    How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

    When Should I Format, How Should I Reinstall

    We can attempt to clean this machine but I can't guarantee that it will be 100% secure afterwards.

    Should you have any questions, please feel free to ask.

    Please let us know what you have decided to do in your next post.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member BloodyPeasant's Avatar
    Join Date
    Jul 2008
    Posts
    3

    Default

    Hi Shaba,
    Thanks for the look. I'm going to reformat the drive.
    Thanks again.

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Do you need help for reformatting?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Junior Member BloodyPeasant's Avatar
    Join Date
    Jul 2008
    Posts
    3

    Default

    No thanks.
    It's just time consuming.
    Have a good day.

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Then see below for my tips for the future:

    Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
    • Download the latest version of Java Runtime Environment (JRE) 6 Update 7 and save it to your desktop.
    • Scroll down to where it saysThe Java SE Runtime Environment (JRE) allows end-users to run Java applications..
    • Click the Download button to the right.
    • Select Windows on platform combobox and check the box that says:
      Accept License Agreement. Click continue.
    • The page will refresh.
    • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    • Close any programs you may have running - especially your web browser.
    • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
    • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
    • Click the Remove or Change/Remove button.
    • Repeat as many times as necessary to remove each Java versions.
    • Reboot your computer once all Java components are removed.
    • Then from your desktop double-click on jre-6u7-windows-i586-p.exe to install the newest version.


    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.


    • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
    • Install Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
      totally free but for real-time protection you will have to pay a small one-time fee. Tutorial on installing & using this product can be found below:

      Malwarebytes' Anti-Malware Setup Guide

      Malwarebytes' Anti-Malware Scanning Guide

    • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

      A tutorial on installing & using this product can be found here:

      Using SpywareBlaster to protect your computer from Spyware and Malware

    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Here are some additional utilities that will enhance your safety



    Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

    Also, please read this great article by Tony Klein So How Did I Get Infected In First Place
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

    Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

    If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •