1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

something launching NTOSKernel

Discussion in 'Malware and Virus Removal Archive' started by MitchellCooley, 2007/02/15.

Thread Status:
Not open for further replies.
  1. 2007/02/15
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    Several times a day I get a message from my Sygate firewall that NTOSKernel has been blocked from accessing the network. I have I have no idea why it would be trying to access the network. I have found an unusual number of Port Scans of my computer - but the Sygate Firewall blocks them all (as far as I know).

    I have AVG, Spybot S&D, and Adaware on my system and they find nothing. I have a Hijack this log and a silent runners log to post (i am concerned about he "Hyperterminal" entry in the silent runners log -- I have no reason to use hyperterminal)

    Scans with AVG, Spybot, Adaware, and Kaspersky on-line find nothing wrong.:confused:

    I am connected to the internet via Wireless Modem.

    If I am in the wrong place please let me know.

    Hyjack this log:

    Logfile of HijackThis v1.99.1
    Scan saved at 12:01:24 AM, on 2/15/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1

    (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\Program Files\Sygate\SPF\smc.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\Explorer.EXE
    C:\Program Files\Spybot - Search &

    Destroy\TeaTimer.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\WINNT\system32\internat.exe
    C:\WINNT\system32\NOTEPAD.EXE
    C:\hjt\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet

    Explorer\Main,Local Page =
    O2 - BHO: (no name) -

    {53707962-6F74-2D53-2644-206D7942484F} -

    C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) -

    {F97DA966-F09D-4cab-BF29-75A0026986EA} - (no

    file)
    O3 - Toolbar: &Radio -

    {8E718888-423F-11D2-876E-00A0C9082467} -

    C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager]

    mobsync.exe /logon
    O4 - HKLM\..\Run: [AVG7_CC]

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [SmcService]

    C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program

    Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition]

    "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe "
    O4 - HKCU\..\Run: [internat.exe] internat.exe
    O4 - Global Startup: WinZip Quick

    Pick.lnk.disabled
    O16 - DPF:

    {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo

    Control) - http://www.sis.com/ocis/OSInfo.cab
    O16 - DPF:

    {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75}

    (CKAVWebScan Object) -

    http://www.kaspersky.com/kos/eng/partner/default

    /kavwebscan_unicode.cab
    O16 - DPF:

    {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX

    Control) -

    http://www.sis.com/ocis/SiSAutodetectNT.cab
    O16 - DPF:

    {17492023-C23A-453E-A040-C7C580BBF700} (Windows

    Genuine Advantage Validation Tool) -

    http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF:

    {6414512B-B978-451D-A0D8-FCFDF33E833C}

    (WUWebControl Class) -

    http://update.microsoft.com/windowsupdate/v6/V5C

    ontrols/en/x86/client/wuweb_site.cab?11647501400

    72
    O16 - DPF:

    {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec

    RuFSI Utility Class) -

    http://security.symantec.com/sscv6/SharedContent

    /common/bin/cabsa.cab
    O23 - Service: AVG7 Alert Manager Server

    (Avg7Alrt) - GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc)

    - GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) -

    GRISOFT, s.r.o. -

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
    O23 - Service: Logical Disk Manager

    Administrative Service (dmadmin) - VERITAS

    Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: Sygate Personal Firewall

    (SmcService) - Sygate Technologies, Inc. -

    C:\Program Files\Sygate\SPF\smc.exe



    Silent Runners Log:

    "Silent Runners.vbs ", revision 49, http://www.silentrunners.org/
    Operating System: Windows 2000
    Output limited to non-default values, except where indicated by "{++} "


    Startup items buried in registry:
    ---------------------------------

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "SpybotSD TeaTimer" = "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ "Safer Networking Limited"]
    "PopUpStopperFreeEdition" = " "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" " [ "Panicware, Inc."]
    "internat.exe" = "internat.exe" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "Synchronization Manager" = "mobsync.exe /logon" [MS]
    "AVG7_CC" = "C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP" [ "GRISOFT, s.r.o."]
    "SmcService" = "C:\PROGRA~1\Sygate\SPF\smc.exe -startgui" [ "Sygate Technologies, Inc."]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\PROGRA~1\SPYBOT~1\SDHelper.dll" [ "Safer Networking Limited"]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension "
    -> {HKLM...CLSID} = "Display Panning CPL Extension "
    \InProcServer32\(Default) = "deskpan.dll" [file not found]
    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext "
    -> {HKLM...CLSID} = "HyperTerminal Icon Ext "
    \InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" [ "Hilgraeve, Inc."]
    "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension "
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" [ "GRISOFT, s.r.o."]
    "{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension "
    -> {HKLM...CLSID} = "AVG7 Find Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" [ "GRISOFT, s.r.o."]
    "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]
    "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]
    "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]
    "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
    AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} "
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" [ "GRISOFT, s.r.o."]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]

    HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
    AVG7 Shell Extension\(Default) = "{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} "
    -> {HKLM...CLSID} = "AVG7 Shell Extension Class "
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" [ "GRISOFT, s.r.o."]
    WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000} "
    -> {HKLM...CLSID} = "WinZip "
    \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" [ "WinZip Computing, Inc."]


    Group Policies {GPedit.msc branch and setting}:
    -----------------------------------------------

    Note: detected settings may not have any effect.

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    Shutdown: Allow system to be shut down without having to log on}


    Active Desktop and Wallpaper:
    -----------------------------

    Active Desktop may be disabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    HKCU\Control Panel\Desktop\
    "Wallpaper" = "C:\Documents and Settings\Mitch\Application Data\Microsoft\Internet Explorer\Internet Explorer Wallpaper.bmp "


    Enabled Screen Saver:
    ---------------------

    HKCU\Control Panel\Desktop\
    "SCRNSAVE.EXE" = "C:\WINNT\system32\logon.scr" [MS]


    Startup items in "Mitch" & "All Users" startup folders:
    -------------------------------------------------------

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    <<!>> "WinZip Quick Pick.lnk.disabled" [null data]


    Enabled Scheduled Tasks:
    ------------------------

    "Spybot - Search & Destroy - Scheduled Task" -> launches: "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe /AUTOCHECK /AUTOFIX /AUTOCLOSE" [ "Safer Networking Limited"]


    Winsock2 Service Provider DLLs:
    -------------------------------

    Namespace Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

    Transport Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
    %SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 13
    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Running Services (Display Name, Service Name, Path {Service DLL}):
    ------------------------------------------------------------------

    AVG E-mail Scanner, AVGEMS, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe" [ "GRISOFT, s.r.o."]
    AVG7 Alert Manager Server, Avg7Alrt, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe" [ "GRISOFT, s.r.o."]
    AVG7 Update Service, Avg7UpdSvc, "C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe" [ "GRISOFT, s.r.o."]
    Sygate Personal Firewall, SmcService, "C:\Program Files\Sygate\SPF\smc.exe" [ "Sygate Technologies, Inc."]


    ----------
    <<!>>: Suspicious data at a malware launch point.

    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + The search for DESKTOP.INI DLL launch points on all local fixed drives
    took 49 seconds.
    ---------- (total run time: 182 seconds)


    Hope someone can help me figure this out. If it is benign that is ok i guess.
     
  2. 2007/02/15
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Hi Mitchell and welcome.

    Neither of the two items you mention are threats at all.

    From an old Sygate forum is this:
    As for the HyperTerminal, I'm not sure exactly what it does, but many users have it on their systems.

    Related to the hticons.dll:
    http://www.liutilities.com/products/wintaskspro/dlllibrary/hticons/
    The rest of your log looks fine, hope that addressed any fears you have.
     

  3. to hide this advert.

  4. 2007/02/15
    MitchellCooley Lifetime Subscription

    MitchellCooley Inactive Thread Starter

    Joined:
    2006/12/02
    Messages:
    1,090
    Likes Received:
    20
    TMerc, thanks. all is well now that I know.

    Mitchell
     
  5. 2007/02/15
    TeMerc

    TeMerc Inactive Alumni

    Joined:
    2006/05/13
    Messages:
    3,226
    Likes Received:
    4
    Glad we could be of assistance.

    Due to resolution this topic is closed.

    If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.