I have two Backdoor viruses on our proxy server which I can't find any information on anywhere. Started getting tons of popups. I have done a dos scan with trendmicro, and also ewido in safe mode. Ewido finds them but can't quarantine or delete. Comes up with an error everytime. The viruses are: "Backdoor.Agent.agw" in C:\WINNT\lsass.exe and also C:\WINNT\lsass.exe_tobedel
eted and "Backdoor.Sdbot.aad" in C:\WINNT\register.exe. Here is my current hijackthis log file. Any help would be greatly appreciated. Thanks in Advance!
RN
Logfile of HijackThis v1.99.1
Scan saved at 4:09:08 PM, on 9/7/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
.exe
C:\WINNT\system32\services
.exe
C:\WINNT\system32\lsass.ex
e
C:\WINNT\system32\svchost.
exe
C:\WINNT\system32\spoolsv.
exe
C:\WINNT\System32\msdtc.ex
e
C:\PROGRA~1\F-Secure\BackW
eb\7681197
\Program\S
ERVIC~1.EX
E
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\WINNT\System32\tcpsvcs.
exe
C:\WINNT\System32\svchost.
exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\F-Secure\Common\FSMA
32.EXE
C:\Program Files\F-Secure\Common\FSMB
32.EXE
C:\Program Files\F-Secure\BackWeb\768
1197\Progr
am\BackWeb
-7681197.e
xe
C:\WINNT\lsass.exe
C:\Program Files\F-Secure\Common\FCH3
2.EXE
C:\Program Files\F-Secure\Common\FAME
H32.EXE
C:\Program Files\F-Secure\Common\FSGK
32.EXE
C:\WINNT\system32\ntfrs.ex
e
C:\WINNT\system32\MSTask.e
xe
C:\WINNT\System32\snmp.exe
C:\WINNT\System32\termsrv.
exe
C:\WINNT\System32\WBEM\Win
Mgmt.exe
C:\WINNT\system32\Dfssvc.e
xe
C:\WINNT\System32\dns.exe
C:\Program Files\F-Secure\Common\FNRB
32.EXE
C:\Program Files\F-Secure\Common\FIH3
2.EXE
C:\Program Files\F-Secure\Anti-Virus\
fsav32.exe
C:\WINNT\System32\svchost.
exe
C:\WINNT\Explorer.EXE
C:\Program Files\F-Secure\Common\FSM3
2.EXE
C:\CCProxy\CCProxy.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Network ICE\BlackICE\blackice.exe
C:\Documents and Settings\Administrator.QSS
ISERVER\De
sktop\Hija
ckThis.exe
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = 64.132.158.199:808
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM3
2.EXE" /splash
O4 - HKLM\..\Run: [CCProxy] C:\CCProxy\CCProxy.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - Global Startup: BlackICE PC Protection.lnk = C:\Program Files\Network ICE\BlackICE\blackice.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.
dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9
BD8C29F7F7
5} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/english/kavwebscan_unicode.cabO16 - DPF: {193C772A-87BE-4B19-A7BB-4
45B226FE9A
1} (ewidoOnlineScan Control) -
http://download.ewido.net/ewidoOnlineScan.cabO16 - DPF: {215B8138-A3CF-44C5-803F-8
226143CFC0
A} (Trend Micro ActiveX Scan Agent 6.5) -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1147272138281O16 - DPF: {74D05D43-3236-11D4-BDCD-0
0C04F9A3B6
1} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2003050501/housecall.antivirus.com/housecall/xscan53.cabO16 - DPF: {81025641-DE98-4F76-902A-4
4F48B3510B
E} -
http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cabO16 - DPF: {94EB57FE-2720-496C-B33F-D
9353C6E23F
7} (F-Secure Online Scanner 2.1) -
http://support.f-secure.com/ols/fscax.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5
009F29E09E
1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = data.qssi.com
O17 - HKLM\System\CCS\Services\T
cpip\..\{2
421C348-59
04-4DE9-B1
B0-B9DD43B
B70F7}: NameServer = 216.136.95.82,216.136.95.3
4
O17 - HKLM\System\CCS\Services\T
cpip\..\{6
7B1E811-34
4E-426F-91
77-A787B60
E3972}: NameServer = 216.136.95.34,216.136.95.8
2
O17 - HKLM\System\CCS\Services\T
cpip\..\{8
C9FACBD-B0
60-4A04-96
C5-C9BDF8B
D2B79}: NameServer = 216.136.95.34,216.136.95.8
2
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = data.qssi.com
O17 - HKLM\System\CS1\Services\T
cpip\..\{2
421C348-59
04-4DE9-B1
B0-B9DD43B
B70F7}: NameServer = 216.136.95.82,216.136.95.3
4
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = data.qssi.com
O17 - HKLM\System\CS2\Services\T
cpip\..\{2
421C348-59
04-4DE9-B1
B0-B9DD43B
B70F7}: NameServer = 216.136.95.82,216.136.95.3
4
O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackW
eb\7681197
\Program\S
ERVIC~1.EX
E
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.
exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\768
1197\Progr
am\fsbwlan
.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB
32.EXE
O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA
.EXE
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA
32.EXE
O23 - Service: IIS Admin Service (IISADMIN) - Unknown owner - C:\WINNT\System32\inetsrv\
inetinfo.e
xe (file missing)
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINNT\lsass.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\rapapp.exe
O23 - Service: Windows Remote Procedure Call Monitoring Service (rpcsvc) - Unknown owner - C:\WINNT\system32\rpcsvc.e
xe (file missing)
O23 - Service: World Wide Web Publishing Service (W3SVC) - Unknown owner - C:\WINNT\System32\inetsrv\
inetinfo.e
xe (file missing)
O23 - Service: Windows Internet Name Service (WINS) (WINS) - Unknown owner - C:\WINNT\System32\wins.exe
(file missing)
O23 - Service: Windows UDP Communication (wudpcom) - Unknown owner - C:\WINNT\system32\wudpcom.
exe (file missing)