1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Wintools Problem - NEW One - Please Help

Discussion in 'Security and Privacy' started by Soccerguy, 2004/06/20.

Thread Status:
Not open for further replies.
  1. 2004/07/01
    Soccerguy

    Soccerguy Inactive Thread Starter

    Joined:
    2004/06/20
    Messages:
    36
    Likes Received:
    0
    Now what?.... Log below - This virus is bugging me soo much - HELP!


    »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»*** freeatlast100.100free.com ***»Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»

    Wed 06/30/2004
    10:59pm up 0 days, 0:02

    Microsoft Windows XP [Version 5.1.2600]
    The type of the file system is FAT32.
    C: is not dirty.

    »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»***LOG1!***»Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»
    Scanning for file(s) in System32...

    »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚» (1) »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»

    »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚» (2) »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»
    **File C:\FINDnFIX\LIST.TXT

    »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚» (3) »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»

    No matches found.

    No matches found.

    »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚» (4) »Â»Ã‚»Ã‚»Ã‚»Ã‚»Ã‚»
    Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.


    »Â»Ã‚»*»Â»Ã‚» Scanning for moved file... »Â»Ã‚»*»Â»Ã‚»
    * result\\?\C:\junkxxx\SQLKEBI.222


    C:\JUNKXXX\
    sqlkebi.222 Thu Jun 10 2004 8:50:20p A.... 57,344 56.00 K

    1 item found: 1 file, 0 directories.
    Total of file sizes: 57,344 bytes 56.00 K

    Power SNiF 1.34 - The Ultimate File Snifferdog. Created Mar 16 1992, 21:09:15.

    Sniffed -> C:\JUNKXXX\SQLKEBI.222

    **File C:\JUNKXXX\SQLKEBI.222
    0000DEBE: 67 44 65 76 69 63 65 00 . 00 53 74 72 65 61 6D 69 gDevice. .Streami
    0000DED3: 63 65 53 65 74 75 70 00 . 32 00 00 00 00 00 E0 01 ceSetup. 2.....Ã*.

    move %WinDir%\System32\sqlkebi.DLL %SystemDrive%\junkxxx\sqlkebi.DLL




    --a-- W32i - - - - 57,344 06-10-2004 sqlkebi.222
    A C:\junkxxx\sqlkebi.222
    File: <C:\junkxxx\sqlkebi.222>

    CRC-32 : D5C9FB2E

    MD5 : C185B36F 9969D3A6 D2122BA7 CBC02249




    »Â»Permissions:
    The Cacls command can be run only on disk drives that use the NTFS file system.Directory "C:\junkxxx\. "
    Permissions:
    NA

    Auditing:
    NA

    Owner: \Everyone

    Primary Group: \Everyone

    Directory "C:\junkxxx\.. "
    Permissions:
    NA

    Auditing:
    NA

    Owner: \Everyone

    Primary Group: \Everyone

    File "C:\junkxxx\sqlkebi.222 "
    Permissions:
    NA

    Auditing:
    NA

    Owner: \Everyone

    Primary Group: \Everyone


    »Â»Size of Windows key:
    (*Default-450 *No AppInit-398 *fake(infected)-448,504,512...)

    Size of HKEY_LOCAL_MACHINE\software\microsoft\Windows NT\CurrentVersion\Windows: 450

    »Â»Dumping Values:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\DeviceNotSelectedTimeout SZ 15
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\GDIProcessHandleQuota DWORD 00002710
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Spooler SZ yes
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\swapdisk SZ
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\TransmissionRetryTimeout SZ 90
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\USERProcessHandleQuota DWORD 00002710
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs SZ

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    DeviceNotSelectedTimeout = 15
    GDIProcessHandleQuota = REG_DWORD 0x00002710
    Spooler = yes
    swapdisk =
    TransmissionRetryTimeout = 90
    USERProcessHandleQuota = REG_DWORD 0x00002710
    AppInit_DLLs =

    »Â»Security settings for 'Windows' key:


    RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
    Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
    This program is Freeware, use it on your own risk!

    Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
    (NI) ALLOW Read BUILTIN\Users
    (IO) ALLOW Read BUILTIN\Users
    (NI) ALLOW Read BUILTIN\Power Users
    (IO) ALLOW Read BUILTIN\Power Users
    (NI) ALLOW Full access BUILTIN\Administrators
    (IO) ALLOW Full access BUILTIN\Administrators
    (NI) ALLOW Full access NT AUTHORITY\SYSTEM
    (IO) ALLOW Full access NT AUTHORITY\SYSTEM
    (NI) ALLOW Full access BUILTIN\Administrators
    (IO) ALLOW Full access CREATOR OWNER

    Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
    Read BUILTIN\Users
    Read BUILTIN\Power Users
    Full access BUILTIN\Administrators
    Full access NT AUTHORITY\SYSTEM



    »Â»Notepad check....

    C:\WINDOWS\
    notepad.exe Thu Aug 23 2001 12:00:00p A.... 66,048 64.50 K

    1 item found: 1 file, 0 directories.
    Total of file sizes: 66,048 bytes 64.50 K

    C:\WINDOWS\SYSTEM32\
    notepad.exe Thu Aug 23 2001 12:00:00p A.... 66,048 64.50 K

    1 item found: 1 file, 0 directories.
    Total of file sizes: 66,048 bytes 64.50 K

    C:\WINDOWS\SYSTEM32\DLLCACHE\
    notepad.exe Thu Aug 23 2001 12:00:00p A.... 66,048 64.50 K

    1 item found: 1 file, 0 directories.
    Total of file sizes: 66,048 bytes 64.50 K
    --a-- W32i APP ENU 5.1.2600.0 shp 66,048 08-23-2001 notepad.exe
    Language 0x0409 (English (United States))
    CharSet 0x04b0 Unicode
    OleSelfRegister Disabled
    CompanyName Microsoft Corporation
    FileDescription Notepad
    InternalName Notepad
    OriginalFilenam NOTEPAD.EXE
    ProductName Microsoft® Windows® Operating System
    ProductVersion 5.1.2600.0
    FileVersion 5.1.2600.0 (xpclient.010817-1148)
    LegalCopyright © Microsoft Corporation. All rights reserved.

    VS_FIXEDFILEINFO:
    Signature: feef04bd
    Struc Ver: 00010000
    FileVer: 00050001:0a280000 (5.1:2600.0)
    ProdVer: 00050001:0a280000 (5.1:2600.0)
    FlagMask: 0000003f
    Flags: 00000000
    OS: 00040004 NT Win32
    FileType: 00000001 App
    SubType: 00000000
    FileDate: 00000000:00000000


    ---------- WIN.TXT
    fùAppInit_DLLsÖÂæG¸Ã¿Ãƒ¿Ãƒ¿C

    ---------- NEWWIN.TXT
    dlAppInit_DLLsnk
    **File C:\FINDnFIX\NEWWIN.TXT
            CD-3Ãÿÿÿvk  Ã*   ÀUDeviceNotSelectedTimeoutðÿÿÿ1 5  Ø(ÃW ° Ãÿÿÿvk  €'   zGDIProcessHandleQuota "þðÿÿÿ9 0  ! Ã*ÿÿÿvk  X   °ÂºSpooler2ðÿÿÿy e s À Ã*ÿÿÿvk  €   =pswapdisk ° ø 8 h  Ãÿÿÿvk  (   R¿TransmissionRetryTimeoutÃÿÿÿvk  €'   0 USERProcessHandleQuota" Ã*ÿÿÿ° ø 8 h  à  Øÿÿÿvk  €   dlAppInit_DLLsnk ¸ 9}w ðÿÿÿlh Øb6 Å“D¯ ÿà Å’ðŸÃˆÃ‚ Pa6 ÿÿÿÿÿÿÿÿ øe6 Â
    **File C:\FINDnFIX\NEWWIN.TXT
    00001338: 01 00 00 00 01 00 64 6C . 5F 44 4C 4C 73 6E 6B 20 ......dl _DLLsnk
    **File C:\FINDnFIX\NEWWIN.TXT
            CD-3Ãÿÿÿvk  Ã*   ÀUDeviceNotSelectedTimeoutðÿÿÿ1 5  Ø(ÃW ° Ãÿÿÿvk  €'   zGDIProcessHandleQuota "þðÿÿÿ9 0  ! Ã*ÿÿÿvk  X   °ÂºSpooler2ðÿÿÿy e s À Ã*ÿÿÿvk  €   =pswapdisk ° ø 8 h  Ãÿÿÿvk  (   R¿TransmissionRetryTimeoutÃÿÿÿvk  €'   0 USERProcessHandleQuota" Ã*ÿÿÿ° ø 8 h  à  Øÿÿÿvk  €   dlAppInit_DLLsnk ¸ 9}w ðÿÿÿlh Øb6 Å“D¯ ÿÿÿnk Å’ðŸÃˆÃ‚ Pa6 ÿÿÿÿÿÿÿÿ øe6 Â
     
  2. 2004/07/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Make sure you have the latest copy of CWShredder Version 1.59. You can download it from the link in my signature.

    Open the FINDnFIX\Files2< Subfolder:
    Run the -> "ZIPZAP.bat" file.
    It will quickly clean the rest and
    will make a copy of the bad file(s) in the same
    folder (junkxxx.zip)

    When done, restart your computer and
    Delete the entire 'FINDnFIX' file and folder(s) and be sure the C:\junkxxx folder
    was deleted (as part of the cleanup process)


    Open CWShredder and with ALL other windows closed, click fix.
    Open Ad-aware and update. Then run a custom full scan and delete all it finds.
    Open My Computer, right click Local disk C: and choose properties, then disk cleanup. Check all boxes except compress old files and OK.

    Reboot and post a new HijackThis log.
     

  3. to hide this advert.

  4. 2004/07/02
    Soccerguy

    Soccerguy Inactive Thread Starter

    Joined:
    2004/06/20
    Messages:
    36
    Likes Received:
    0
    So far no problems but I have not opened my Eudora yet (which is where I suspect a problem (virus) may lay. I'll post a follow up shortly but here is my HJT log so far (prior to opening Eudora)

    Logfile of HijackThis v1.97.7
    Scan saved at 6:55:58 PM, on 7/2/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLACSD.EXE
    C:\WINDOWS\System32\CTsvcCDA.EXE
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\wanmpsvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Norton AntiVirus\SAVScan.exe
    C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\ATI Multimedia\main\ATISched.EXE
    C:\WINDOWS\System32\ctfmon.exe
    C:\WINDOWS\System32\devldr32.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\AIM\aim.exe
    C:\Program Files\AOL Companion\companion.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HiJack This\HijackThis.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Common Files\aolshare\Aolunins_us.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/?u
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll
    O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~2\AdvTools\ADVCHK.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [ATI Scheduler] C:\Program Files\ATI Multimedia\main\ATISched.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
    O4 - Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
    O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
    O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: AOL Toolbar (HKLM)
    O9 - Extra 'Tools' menuitem: AOL Toolbar (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: AIM (HKLM)
    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
     
  5. 2004/07/02
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Looking much better. Fix these, reboot and post another log.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k


    Do another RAV scan and post the report too.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.