I have a client's computer that has been cleaned of many trojans/viruses including the "WinAntivirusPro". At this point when I try to go to housecalls.trendmicro.com for an online scan, it returns "page cannot be displayed", while a ping to trendmicro.com, symantec.com, ca.com, and many others return 127.0.0.1.
I checked the HOSTS file (and LMHOSTS etc), but they haven't been modified for over a year and the HOSTS file did not contain anything but the 5 entries we put into the computer for resolution of WAN connections. As a matter of fact, I even removed the HOSTS file completely and still get the same reply from the localhost when trying to ping a antivirus/spyware related web-address.
I have run various fixes for trojans that do similar (but typically modify the HOSTS file) including AGOBOT and SmitFraud.
I've checked and rechecked DNS on several of our own server as well as public DNS servers. Most sites resolve fine unless they are an anti-malware type site. When I put a bogus IP for the DNS server, nothing resolves (as expected) except for the sites like symentec.com (reply from 127.0.0.1).
We have also attempted an install (early on in the process) of Firefox which installs fine, but will not run (starts to run but kills -- as shown in process explorer).
As well, upon removal of one of the many trojans, the application mapping for running .exe files was lost. A patch was applied and this was restored.
I'm pretty well at my wits end here, and need some advise. Format/reinstall is not an option on this machine unfortunately.
I'm including my HijackThis log:
--------------------------
----------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:54:35 PM, on 6/4/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
C:\WINDOWS\SYSTEM32\DNTUS2
6.EXE
C:\WINDOWS\SYSTEM32\DWRCS.
EXE
C:\Program Files\Dell\OpenManage\Clie
nt\Iap.exe
C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SYSTEM32\DWRCST
.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
F2 - REG:system.ini: Shell=
F2 - REG:system.ini: UserInit=C:\Windows\System
32\userini
t.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
2.dll
O3 - Toolbar: (no name) - {90B8B761-DF2B-48AC-BBE0-B
CC03A819B3
B} - (no file)
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0
090271D4F8
8} - (no file)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {15D73F88-277E-42EC-BE97-C
64E1C6A18D
9} -
http://data-1/cbopracticemanager/Install/CPOPM04Client/CPOPM04Client.cabO16 - DPF: {17492023-C23A-453E-A040-C
7C580BBF70
0} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {1E6AC13B-5ADA-4810-A79B-9
658AEF060C
8} -
http://data-1/centricity/Install/McKesson04/McKesson04.cabO16 - DPF: {329E2905-EDCC-4B43-8243-9
85AC1D9D4F
F} -
http://data-1/bravo/Install/ARBCBS04/ARBCBS04.cabO16 - DPF: {41F17733-B041-4099-A042-B
518BB6A408
C} -
http://a1408.g.akamai.net/7/1408/9955/20031016/akamai.info.apple.com/iTunes4/WW/win/061-0840.20031016.sAc49/iTunesSetup.exeO16 - DPF: {4869BC42-91D5-433E-8557-F
4285DCA0B6
F} -
http://data-1/cbopracticemanager/Install/CPOPM04GoldClientSP3/CPOPM04GoldClientSP3.cabO16 - DPF: {5C09FD7C-B414-43CE-8A41-E
BBA80EB0FF
C} -
http://data-1/bravo/Install/McKesson04/McKesson04.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-3
98534BB899
9} -
http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/autocomplete.cabO16 - DPF: {C93C8624-4FC1-4BC4-9FC9-C
AB94FF8208
F} -
http://data-1/cbopracticemanager/Install/CPOPM04GoldClientSP2a/CPOPM04GoldClientSP2a.cabO16 - DPF: {E5855096-43F4-47CF-8723-B
AFC1759AFD
C} -
http://data-1/bravo/Install/CPOPM04GoldClient710/CPOPM04GoldClient710.cabO16 - DPF: {E839F0A1-4D68-472A-BBB8-0
8FA530581C
F} (MBCInstaller 6.0 object) -
http://data-1/centricity/Install/MBCINSTaller60.dllO16 - DPF: {F12CFEEA-7984-4AD4-BADD-0
2C315148F8
3} -
http://server-1/pfs/Install/MPM02SP1ClientHF4/Default.cabO16 - DPF: {F839F0A1-4D68-472A-BBB8-0
8FA530581C
F} (GEMSInstaller 7.0 object) -
http://data-1/bravo/Install/MBCINSTaller70.dllO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = CBO.LOCAL
O17 - HKLM\Software\..\Telephony
: DomainName = CBO.LOCAL
O17 - HKLM\System\CCS\Services\T
cpip\..\{A
FD5B35E-B6
DB-4716-8F
3B-200F816
D9CB4}: NameServer = 4.2.2.1
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = CBO.LOCAL
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = CBO.LOCAL
O17 - HKLM\System\CS3\Services\T
cpip\Param
eters: Domain = CBO.LOCAL
O20 - Winlogon Notify: jkkijHBT - jkkijHBT.dll (file missing)
O20 - Winlogon Notify: __c006A764 - C:\WINDOWS\system32\__c006
A764.dat (file missing)
O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\DefWat
ch.exe
O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DNTUS2
6.EXE
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DWRCS.
EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
Updater\GoogleUpdaterServi
ce.exe
O23 - Service: Iap - Dell Computer Corporation - C:\Program Files\Dell\OpenManage\Clie
nt\Iap.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc
.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMAN
T~1\Rtvsca
n.exe
--
End of file - 5048 bytes
--------------------------
-----
Thanks in advance,
Patrick Ring