Hi
While I was away on holiday last week I got a call from a friend who was house/cat sitting for us saying,
"Dont panic but I think I have managed to pick up a virus on your PC."
He says it came from some browser highjack where he clicked on the wrong button or something. Great...
Much worse, he says he also clicked on the wrong button when Tea Timer popped up asking permission for a registry change!! This may be due to the annoying 'button text not displaying properly bug.'
He says that in a desperate attempt to save the situation he ran AVG, Ad-Aware, Spybot and Ewido, all of which crashed. Some scans showed that it wasn't until they reached the System32 Folder that they crashed. He says that before they crashed a couple of scans referred to various corrupted or malicious files in System32.
This is where it gets really worrying...
He decided to manually delete them but couldn't gain access through explorer to System32. Eventually he was able to locate the offending(?) files via windows search and then deleted them.
I thought that maybe he couldn't gain access to System32 because he was only using an account with limited permissions. If only that was the case!!
When I got back I tried to access the folder from the Administrator's account to discover the same problem. You just get a blank window and have to end the process with task manager.
I have since run an online Bit Defender scan which also crashed at C:\WINDOWS\System32\ZoneLabs\
At this point it was saying it was reading file 27052 out of 27050 (huh?)
Before that it had found 2 Viruses and 5 Infected files which it couldn't disinfect but it said it had deleted them. They were as folows:
C:\WINDOWS\System32\dmhip.exe
C:\WINDOWS\System32\dmjup.exe
C:\WINDOWS\System32\dmkif.exe
C:\WINDOWS\System32\dmtold.exe
- All of which were infected with MemScan:Trojan.Agent.QB
and
C:\WINDOWS\System32\tiryt.exe
- Which was infected with MemScan:Trojan.Downloader.Agent.ACH
After this I ran Spybot in Safe Mode:
It crashed while running bot check on file 5125 of 406804: Win32.Sober
Next came an Ewido scan:
It crashed at C:\WINDOWS\temp - but not before it found these infections:
Process: [444]VM_00D60000 Infection: Downloader.Agent.uj
Process: [468]VM_00C70000 Infection: Downloader.Agent.uj
Process: [1552]VM_009D0000 Infection: Downloader.Agent.uj
Process: [2004]VM_00AD0000 Infection: Downloader.Agent.uj
Process: [2028]VM_00390000 Infection: Downloader.Agent.uj
Process: [164]VM_00A20000 Infection: Downloader.Agent.uj
Process: [180]VM_003B0000 Infection: Downloader.Agent.uj
Process: [188]VM_00960000 Infection: Downloader.Agent.uj
Process: [284]VM_009E0000 Infection: Downloader.Agent.uj
Process: [324]VM_00880000 Infection: Downloader.Agent.uj
Process: [856]VM_009F0000 Infection: Downloader.Agent.uj
Process: [1180]VM_00A20000 Infection: Trojan.small.fb
Process: [928]VM_008B0000 Infection: Downloader.Agent.uj
I was asked if I wanted to delete these, I clicked yes so hopefully they are all gone now.
(who can tell??)
Last of all here's my HighJackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 18:42:13, on 15/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\1_Non Windows Software\Administrative\Ewido antimalware\prog files\ewido
anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\1_Non Windows Software\Administrative\Zonealarm\Prog Files\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\1_Non Windows Software\Administrative\Spybot\Prog Files\Spybot - Search &
Destroy\TeaTimer.exe
C:\Program Files\1_Non Windows Software\Graphics\Acrobat 5\Prog Files\Distillr\AcroTray.exe
C:\Program Files\BT Broadband\Help\bin\mpbtn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\1_Non Windows Software\Administrative\Hijack This\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sra3.guardian.co.uk/home/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sra3.guardian.co.uk/home/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\1_non windows
software\graphics\acrobat 5\prog files\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\1_NONW~1\ADMINI~1\Spybot\PROGFI~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\1_Non Windows
Software\Administrative\Zonealarm\Prog Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\1_Non Windows Software\Administrative\Spybot\Prog
Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\1_Non Windows Software\Graphics\Acrobat 5\Prog
Files\Distillr\AcroTray.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\1_Non Windows Software\Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\1_NONW~1\Office\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file
missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 -
{85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.bitdefender.com
O15 - Trusted Zone: http://www.google.co.uk
O15 - Trusted Zone: http://sra3.guardian.co.uk
O15 - Trusted Zone: *.markusjannson.net
O15 - Trusted Zone: *.msn.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.spammotel.com
O15 - Trusted Zone: www.sunbelt-software.com
O15 - Trusted Zone: http://www.youtube.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{62BC2843-ACBE-4C73-84B8-E147FD4844B2}: NameServer =
85.255.113.147,85.255.112.188
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.147 85.255.112.188
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.147 85.255.112.188
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.147 85.255.112.188
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems
Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\1_Non Windows
Software\Administrative\Ewido antimalware\prog files\ewido anti-malware\ewidoctrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Please Help, I'm at the end of the line here... I know it must be bad if I can't even get into the System32 folder.
Any help would be most gratefully received.
Glen
While I was away on holiday last week I got a call from a friend who was house/cat sitting for us saying,
"Dont panic but I think I have managed to pick up a virus on your PC."
He says it came from some browser highjack where he clicked on the wrong button or something. Great...
Much worse, he says he also clicked on the wrong button when Tea Timer popped up asking permission for a registry change!! This may be due to the annoying 'button text not displaying properly bug.'
He says that in a desperate attempt to save the situation he ran AVG, Ad-Aware, Spybot and Ewido, all of which crashed. Some scans showed that it wasn't until they reached the System32 Folder that they crashed. He says that before they crashed a couple of scans referred to various corrupted or malicious files in System32.
This is where it gets really worrying...
He decided to manually delete them but couldn't gain access through explorer to System32. Eventually he was able to locate the offending(?) files via windows search and then deleted them.
I thought that maybe he couldn't gain access to System32 because he was only using an account with limited permissions. If only that was the case!!
When I got back I tried to access the folder from the Administrator's account to discover the same problem. You just get a blank window and have to end the process with task manager.
I have since run an online Bit Defender scan which also crashed at C:\WINDOWS\System32\ZoneLabs\
At this point it was saying it was reading file 27052 out of 27050 (huh?)
Before that it had found 2 Viruses and 5 Infected files which it couldn't disinfect but it said it had deleted them. They were as folows:
C:\WINDOWS\System32\dmhip.exe
C:\WINDOWS\System32\dmjup.exe
C:\WINDOWS\System32\dmkif.exe
C:\WINDOWS\System32\dmtold.exe
- All of which were infected with MemScan:Trojan.Agent.QB
and
C:\WINDOWS\System32\tiryt.exe
- Which was infected with MemScan:Trojan.Downloader.Agent.ACH
After this I ran Spybot in Safe Mode:
It crashed while running bot check on file 5125 of 406804: Win32.Sober
Next came an Ewido scan:
It crashed at C:\WINDOWS\temp - but not before it found these infections:
Process: [444]VM_00D60000 Infection: Downloader.Agent.uj
Process: [468]VM_00C70000 Infection: Downloader.Agent.uj
Process: [1552]VM_009D0000 Infection: Downloader.Agent.uj
Process: [2004]VM_00AD0000 Infection: Downloader.Agent.uj
Process: [2028]VM_00390000 Infection: Downloader.Agent.uj
Process: [164]VM_00A20000 Infection: Downloader.Agent.uj
Process: [180]VM_003B0000 Infection: Downloader.Agent.uj
Process: [188]VM_00960000 Infection: Downloader.Agent.uj
Process: [284]VM_009E0000 Infection: Downloader.Agent.uj
Process: [324]VM_00880000 Infection: Downloader.Agent.uj
Process: [856]VM_009F0000 Infection: Downloader.Agent.uj
Process: [1180]VM_00A20000 Infection: Trojan.small.fb
Process: [928]VM_008B0000 Infection: Downloader.Agent.uj
I was asked if I wanted to delete these, I clicked yes so hopefully they are all gone now.
(who can tell??)
Last of all here's my HighJackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 18:42:13, on 15/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\1_Non Windows Software\Administrative\Ewido antimalware\prog files\ewido
anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\1_Non Windows Software\Administrative\Zonealarm\Prog Files\ZoneAlarm\zlclient.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe
C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\1_Non Windows Software\Administrative\Spybot\Prog Files\Spybot - Search &
Destroy\TeaTimer.exe
C:\Program Files\1_Non Windows Software\Graphics\Acrobat 5\Prog Files\Distillr\AcroTray.exe
C:\Program Files\BT Broadband\Help\bin\mpbtn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\1_Non Windows Software\Administrative\Hijack This\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sra3.guardian.co.uk/home/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://sra3.guardian.co.uk/home/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\1_non windows
software\graphics\acrobat 5\prog files\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\1_NONW~1\ADMINI~1\Spybot\PROGFI~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\1_Non Windows
Software\Administrative\Zonealarm\Prog Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\1_Non Windows Software\Administrative\Spybot\Prog
Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Acrobat Assistant.lnk = C:\Program Files\1_Non Windows Software\Graphics\Acrobat 5\Prog
Files\Distillr\AcroTray.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\1_Non Windows Software\Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\1_NONW~1\Office\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file
missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 -
{85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.adobe.com
O15 - Trusted Zone: http://www.bitdefender.com
O15 - Trusted Zone: http://www.google.co.uk
O15 - Trusted Zone: http://sra3.guardian.co.uk
O15 - Trusted Zone: *.markusjannson.net
O15 - Trusted Zone: *.msn.com
O15 - Trusted Zone: http://www.pandasoftware.com
O15 - Trusted Zone: *.passport.com
O15 - Trusted Zone: *.spammotel.com
O15 - Trusted Zone: www.sunbelt-software.com
O15 - Trusted Zone: http://www.youtube.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{62BC2843-ACBE-4C73-84B8-E147FD4844B2}: NameServer =
85.255.113.147,85.255.112.188
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.147 85.255.112.188
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.147 85.255.112.188
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.147 85.255.112.188
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems
Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\1_Non Windows
Software\Administrative\Ewido antimalware\prog files\ewido anti-malware\ewidoctrl.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC -
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Please Help, I'm at the end of the line here... I know it must be bad if I can't even get into the System32 folder.
Any help would be most gratefully received.
Glen