Quantcast

Maximum PC

It is currently Sun May 19, 2013 4:08 am

All times are UTC - 8 hours




Post new topic Reply to topic  [ 12 posts ] 
Author Message
 Post subject: Strange Malware Infection
PostPosted: Sun Jan 22, 2012 8:20 pm 
Klamath
Klamath
User avatar

Joined: Thu Aug 14, 2008 8:44 am
Posts: 214
I'm starting a new thread because my thread titled "HijackThis Log" isn't serving me well considering my problem is no longer about the log.

Awhile ago I receive a computer along with the complaint that it would "freeze up" whenever visiting a second website. Upon investigation, I did not get it to freeze, but I noticed that when closing out of Internet Explorer, the iexplorer.exe process remained running until killed with the Task Manager. Suspecting malware, I ran a scan with mbam. It found some orphaned registry entries and let me know that Windows Security Center was disabled. I removed the registry entries and enabled Security Center and proceeded to scan with SUPERAntispyware. It told me I had a trojan, which I removed. Afterward, iexplorer.exe seemed to terminate properly. I then ran HijackThis and posted the log here. A very helpful user helped me sort through it, and I removed a couple of entries.

I thought I was done, so I ran Microsoft Update to finish things off. When it finished searching for updates, I was disturbed to find that it wasn't listing any Office XP updates, even though I checked and it was installed with no service packs. I started to investigate this issue when I noticed that images from Office.com were not loading properly. Upon further investigation, images were not loading properly from a number of sites that malware may be concerned about. For instance, microsoft.com, office.com, avg.com, and mcafee.com all load improperly, while other sites, such as maximumpc.com and google.com, do load properly. This made me suspect malware once again. I tried several additional scanners, such as Windows malicious software removal tool, and McAfee stinger, but they found nothing. I also ran PCPitstop exterminator, which found a trojan, but it told me that I had to pay to remove the trojan. (PCPitstop used to be good :( ) Finally, I ran autoruns and saw several services that had random names, descriptions pulled from real services, and all pointed to a nonexistant dll with the same name but in different locations. I tried deleting them, but they always come back, making me really suspect malware.

Can someone tell me what's next? I'm at a loss for this one.

Here's the latest HijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:07:22 PM, on 1/20/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &ESPN - {AE6F2894-AF10-4C9C-B16E-1DFC6FF8C0C6} - C:\Program Files\ESPN\Toolbar\DIGToolBar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [AVG_TRAY] "C:\Program Files\AVG\AVG2012\avgtray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Button Manager.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: McAfee Security Scan Plus.lnk = ?
O4 - Global Startup: NewsCenter 13 NOW.lnk = C:\Program Files\Common Files\NewsCenter 13 NOW\TrueWeather.exe
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... oader5.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/binary/Me ... b31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/binary/ms ... b56986.cab
O16 - DPF: {32C3FEAE-0877-4767-8C20-62A5829A0945} - http://static.ak.facebook.com/fbplugin/ ... loader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/EN-US/a-U ... E_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 9960208312
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/200 ... ader55.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/binary/Me ... b31267.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - https://www.adpalliance.com/web1000/msrdp.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/binary/ZI ... b47946.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.~LINK BROKEN BY MANAGEMENT~/binary/Me ... b56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/s ... wflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/fi ... tup163.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2012\avgwdsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

--
End of file - 9087 bytes


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Sun Jan 22, 2012 9:28 pm 
Thoroughbred
Thoroughbred
User avatar

Joined: Sat May 07, 2011 12:30 pm
Posts: 1922
Location: A place not actively occupied by something else.
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
This one is unknown.

Other than that nothing jumps out at me.
Have you tried running AVG? Download it on another PC. Better yet, get this. It's free and works well on things that HijackThis can't catch.
HijackThis is a good tool, but it can't catch everything. It only shows stuff that has the potential to hijack your browser, such as DLLs, exes, and ActiveX controls. The AVG cd will get everything else that's bad.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Mon Jan 23, 2012 1:35 am 
Team Member*
Team Member*
User avatar

Joined: Sun Aug 22, 2004 6:22 pm
Posts: 1982
Location: FL
winmaster wrote:
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)

These entries seem to have some issues.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Mon Jan 23, 2012 5:19 am 
[Team Member]
[Team Member]

Joined: Sat Jun 26, 2004 4:31 am
Posts: 10883
Location: Home Sweet Home
I just fixed a friends computer at his business that had problems with redirection with his browsers.

I used Smitfraudfix first, then Combofix and finally Malwarebytes in Safe Mode with Networking and it cleaned out all the viruses he had and the internet worked fine in all browsers afterwards. The first two are very powerful tools, one or two people in this forum said it messed up their system when they used it. I have been using this combination for a couple of years with great success and never had a system messed up by them.

Nasty


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Mon Jan 23, 2012 8:42 am 
Thoroughbred
Thoroughbred
User avatar

Joined: Sat May 07, 2011 12:30 pm
Posts: 1922
Location: A place not actively occupied by something else.
Maybe it's the order of use.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Wed Jan 25, 2012 3:05 pm 
Little Foot
Little Foot

Joined: Tue Jul 06, 2010 5:39 pm
Posts: 122
check your program list - uninstall all extraneous toolbars and any updaters for the same.

make sure your sunjava client is up to date.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Wed Jan 25, 2012 3:10 pm 
Thoroughbred
Thoroughbred
User avatar

Joined: Sat May 07, 2011 12:30 pm
Posts: 1922
Location: A place not actively occupied by something else.
I'd just leave them if you have the space, and disable or uninstall them from inside the browser. If there's anything insidious lurking inside a toolbar, then uninstalling it won't kill it. AVG will pick up any insidious objects, like the virus your mom accidentally downloaded.

Secunia PSI will tell you if all your programs are up to date. It's easier than manually checking Reader, Flash, and Java.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Wed Jan 25, 2012 8:27 pm 
Klamath
Klamath
User avatar

Joined: Thu Aug 14, 2008 8:44 am
Posts: 214
I ran the AVG rescue CD and it found nothing.

I then followed Nasty's instructions. Afterward, I deleted the entries in HijackThis that were suspicious. Finally, I figured out how to get rid of the suspicious services in Autoruns. It turned out I didn't have permission to delete those entries, so I gave myself full control and then deleted them.

IE is still acting weird.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Wed Jan 25, 2012 9:19 pm 
Thoroughbred
Thoroughbred
User avatar

Joined: Sat May 07, 2011 12:30 pm
Posts: 1922
Location: A place not actively occupied by something else.
At this point, I'd just DBAN the drive and reinstall Windows.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Wed Jan 25, 2012 9:25 pm 
Thunderbird
Thunderbird
User avatar

Joined: Fri Feb 08, 2008 8:54 am
Posts: 889
Location: In front of the "Command Center"
Just for diagnostic purposes, have you installed any other browsers to see how they run? I would try Firefox or Chrome (do not import IE settings during install) just to see how an alternative acts. If everything is okay using another browser, then it's likely that IE or the plugins just aren't configured properly.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Wed Jan 25, 2012 9:43 pm 
Thoroughbred
Thoroughbred
User avatar

Joined: Sat May 07, 2011 12:30 pm
Posts: 1922
Location: A place not actively occupied by something else.
vig1lant3 wrote:
Just for diagnostic purposes, have you installed any other browsers to see how they run? I would try Firefox or Chrome (do not import IE settings during install) just to see how an alternative acts. If everything is okay using another browser, then it's likely that IE or the plugins just aren't configured properly.

I thought we'd already tried that... Guess not.


Top
  Profile  
 
 Post subject: Re: Strange Malware Infection
PostPosted: Thu Jan 26, 2012 1:19 am 
Team Member*
Team Member*
User avatar

Joined: Sun Aug 22, 2004 6:22 pm
Posts: 1982
Location: FL
I usually try the same thing I have had IE act weird on me too. I usually have a USB thumb drive that I keep all 3 browsers on including all the other programs for cleaning and troubleshooting. It is a invaluable tool.


Top
  Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 12 posts ] 

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group