I have a client with a Win XP Media Center Edition machine. It is very infected. I ran Avira Antivir and Spysweeper which found a couple of things. Uninstalled those and then ran the trial version of AVG 8.0 Internet Security which found many more things. However, the computer is still infected.
These are the primary symptoms:
1) The Time down on the taskbar is in military time and has the words" "Virus Alert!" After it. All files that show a date/time also have these words in the time.
2) A popup keeps coming up that says "Windows Security Alert: Windows has detected an Internet attack attempt. Somebody's trying to infect your PC with spyware or harmful viruses. Run full system scan now to protect your PC from Internet Attacks, highjacking attamps, and spyware. Click here to download sypware remover for total protection.
3) A balloon message shows up on the taskbar saying "System Alert: System detected virus activities.. These may impact the performance of your computer. Please, use recommend antisypware software to protect your system from parasite programs."
4) Another popup saying "Spyware Alert: Security Warning! Worm.Win32.Netbooster detected on your machine . . . blah, blah, blah."
5) The client also uses AOL 9. It keeps opening itself, over and over, even when you close it"
6) The Task Manager has been disabled message comes up when you press Ctrl-Alt-Del.
My questions:
A) I have attached a highjackthis log to show what's running on the computer. How do I interpret this? and remove the problems?
B) Is there another piece of software that will do a better job of getting rid of most of the malware? I have always had very good luck with Avira, AVG, and Spysweeper.
Also, this client does not seem to have the Win XP Media Center Edition CD. I told him it might be easier to wipe and start over, but he doesn't have the CD.
Thanks so much!
Log:
ogfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 14:25: VIRUS ALERT!, on 6/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
E:\AVG\AVG8\avgwdsvc.exe
E:\AVG\AVG8\avgfws8.exe
C:\WINDOWS\eHome\ehRecvr.e
xe
C:\WINDOWS\eHome\ehSched.e
xe
E:\Google\Common\Google Updater\GoogleUpdaterServi
ce.exe
E:\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
E:\AVG\AVG8\avgam.exe
E:\AVG\AVG8\avgrsx.exe
E:\AVG\AVG8\avgnsx.exe
C:\WINDOWS\ehome\ehtray.ex
e
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
E:\AVG\AVG8\avgemc.exe
C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
E:\Dell Photo AIO Printer 964\dlcjmon.exe
E:\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\Common Files\AOL\1170810117\ee\AO
LSoftware.
exe
E:\Java\jre1.6.0_03\bin\ju
sched.exe
E:\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe
E:\AVG\AVG8\avgtray.exe
E:\slide\slide.exe
E:\Google\GoogleToolbarNot
ifier\Goog
leToolbarN
otifier.ex
e
C:\WINDOWS\system32\ctfmon
.exe
C:\WINDOWS\system32\dllhos
t.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\eHome\ehmsas.ex
e
C:\Program Files\Common Files\AOL\1170810117\ee\ao
lsoftware.
exe
C:\WINDOWS\system32\dlcjco
ms.exe
E:\iPod\bin\iPodService.ex
e
C:\WINDOWS\system32\wuaucl
t.exe
I:\Computer Repair Utility Kit\Virus and Malware Removal Tools\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D
1CA6FB9C90
D} - E:\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: (no name) - rsion - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Common Files\Adobe\Acrobat\Active
X\AcroIEHe
lper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4
C09146192C
A} - C:\Program Files\Real\RealPlayer\rpbr
owserrecor
dplugin.dl
l
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4
E65E497C8C
0} - E:\AVG\AVG8\avgssie.dll
O2 - BHO: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-6
9AB0FA17AE
7} - E:\alot\bin\alot.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - E:\Java\jre1.6.0_03\bin\ss
v.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8
EA1C75885F
9} - E:\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
E66B5AD205
D} - E:\Google\GoogleToolbarNot
ifier\3.0.
1225.9868\
swg.dll
O2 - BHO: QXK Olive - {E4DCBEAD-D329-4EAB-9C5D-0
9DACE8CA67
9} - C:\WINDOWS\ksendlbtvnl.dll
(file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - e:\google\googletoolbar1.d
ll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-A
A305ED9D92
2} - E:\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-6
9AB0FA17AE
7} - E:\alot\bin\alot.dll
O3 - Toolbar: vrmdtneg - {860E2925-FAD4-4BE9-848C-E
96B52A4135
1} - C:\WINDOWS\vrmdtneg.dll (file missing)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.ex
e
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Dell\Media Experience\DMXLauncher.exe
"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\DLC
Jtime.dll,
_RunDLLEnt
ry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "E:\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "E:\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [AOLDialer] "C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"
O4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1170810117\ee\AO
LSoftware.
exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Java\jre1.6.0_03\bin\j
usched.exe
"
O4 - HKLM\..\Run: [iTunesHelper] "E:\iTunes\iTunesHelper.ex
e"
O4 - HKLM\..\Run: [QuickTime Task] "E:\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
ched.exe" -osboot
O4 - HKLM\..\Run: [%PROVIDERID%] "bin\sprtcmd.exe" /P %PROVIDERID%
O4 - HKLM\..\Run: [AntiMalwareGuard] E:\AntiMalwareGuard\amg.ex
e
O4 - HKLM\..\Run: [AVG8_TRAY] E:\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Slide.exe] e:\slide\slide.exe
O4 - HKCU\..\Run: [swg] E:\Google\GoogleToolbarNot
ifier\Goog
leToolbarN
otifier.ex
e
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - Startup: KybtecWcCaller.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O6 - HKCU\Software\Policies\Mic
rosoft\Int
ernet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Policies\
System, DisableRegedit=1
O8 - Extra context menu item: &AOL Toolbar Search - e:\aol\aol toolbar 5.0\resources\en-US\local\
search.htm
l
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\
GPhotos.sc
r/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11
\EXCEL.EXE
/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - E:\Java\jre1.6.0_03\bin\ss
v.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - E:\Java\jre1.6.0_03\bin\ss
v.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B
4C75499B57
8} - E:\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - E:\MICROS~1\OFFICE11\REFIE
BAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-0
0C0F0318AF
E} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-C
C0A30F9028
C} (MiniBugTransporterX Class) -
http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1167340143359O16 - DPF: {7B62F6EE-D046-11D3-9C5E-0
060082627F
7} (TWDownloader Class) -
https://securemail.hctx.net/download/TWDownload.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {E596DF5F-4239-4D40-8367-E
BADF016591
7} -
http://privacyprotector.com/.freeware/cab/installprivacyprotector.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-F
BDDE494F8D
1} - E:\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: E:\\Google\GOOGLE~2\GOEC62
~1.DLL,E:\
Google\GOO
GLE~2\GOEC
62~1.DLL,a
vgrsstx.dl
l
O21 - SSODL: wpvmqosg - {86A580E7-2727-4727-B588-8
B177FA621F
A} - C:\WINDOWS\wpvmqosg.dll
O21 - SSODL: xvorfwbd - {EE379605-1337-4640-9E3A-D
9924D05018
A} - C:\WINDOWS\xvorfwbd.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-0
0A0C90312E
1} - C:\WINDOWS\system32\browse
ui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3
078302C203
0} - C:\WINDOWS\system32\browse
ui.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\A
CS\AOLacsd
.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - E:\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - E:\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - E:\AVG\AVG8\avgfws8.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjco
ms.exe
O23 - Service: DSBrokerService - Unknown owner - E:\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-0930
07-112848)
- Google - E:\\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - E:\Google\Common\Google Updater\GoogleUpdaterServi
ce.exe
O23 - Service: iPod Service - Apple Inc. - E:\iPod\bin\iPodService.ex
e
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NC
S\Sync\Net
Svc.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter
) - SupportSoft, Inc. - E:\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 10261 bytes
Start Free Trial