Hijackthis log looks clean. the virus could be a rootkit and Hijackthis couldn't detect anything. Please run GMER and attach the log file
Main Topics
Browse All TopicsLately I noticed lots unusual files under c:\windows\temp. Tried Symantec, Spybot, Ad-Aware and Prevx. None of them can remove them completely. I can delete them, but they will keep coming back. Symantec can only detect 00000000.zip and quarantined the file, but they'll come back again and again. Here is a list of files that are in the temp folder.
4504E2AF.qsp
qsp18.tmp
NSD19.tmp
00000000.txt
00000000.zip
4504E272.qsp
4504E283.qsp
qsp17.tmp
etc......
I also found someone had the same problem (http://www.spywarepoint.c
Anyone has any idea?
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
@asllin
Please do the following:
1) Run CCleaner again to clear TEMP folders
2) Open SEP > Quarantine > delete all
3) Download & run Symantec's Intelligent Updater to install latest virus definitions and overrides corrupted ones.
http://definitions.symante
4) Run a full virus scan in safe mode
This guy is so new (actually a new flavor of an old one) that almost every link reports it; but, has no cure.
However; according to this posting ( http://www.spywarepoint.co
OK, IMHO, Symantec probably won't cut it anyway and, as this is a new flavor of the old guy, we may have to dig into it and brute force dig it out.
Since this is server 2003, one thought I have is to check in users and shares to see if there is an odd user logged in and whether Open Files in Shared Folders lists any of the files. If there is an odd user, kick them out and disable the account temporarilly which may allow Norton to find something.
If you get no joy that way, try Driver Manager ( http://www.freewarefiles.c
1) Download & run Symantec's Intelligent Updater to install latest virus definitions and overrides corrupted ones.
http://definitions.symante
This just to install the latest virus definitions. Some corrupted ones could produce similar issues. This is not a virus scanning utility or removal tool.
2) Regarding the error, check the following KB article:
http://service1.symantec.c
3) To run a virus scan in safe mode, check the following KB article:
http://service1.symantec.c
As an alternative, download and install Kaspersky anti virus. Get all updates and create system restore CD. Boot it and scan for viruses, or boot to "safe mode" and scan there. Kaspersky can scan in safe mode. You probably have to disable system restore to clean your system completely, so before doing any scanning make a System state backup with ntbackup.
No, but to make sure that your system is rootkit-free.
1) Please download RootkitRevealer then extract it to C:\
(http://download.sysintern
2) From CMD, type the following command:
C:\rootkitrevealer.exe -a c:\rootkit.log
3) Attach the log file here
O16 - DPF: {AA299E98-6FB5-409F-99D3-D
I understand this is a legit application for remote access ala Bomgar / Webex ,etc... ?
if this is a legit installation that you know should exist, then I can say the HJT log looks fine.
in order to ensure the startup is clean & nothing is bypassing HJT , let us try to see a log for Autoruns
please download & run the tool, let it load startup , then File>save>Autoruns.arn
rename
In Process Explorer (see my earlier post), you can do Find -> Handle, type in one of those pesky files (4504E2AF.qsp, for example), and it will find the process which is using it. That should be a big help towards pointing us in the right direction! You then have the ability to kill the process which might let Norton see the bastard.
Also, I regularly use a device manager with the SET DEVMGR_SHOW_NONPRESENT_DEV
Were it not for the rogue files you report, I would be suggesting you use the free version of http://www.hdtune.com to see if one of your drives is on the verge of failing and will mention that it sure wouldn't hurt anything to check.
Hi xmachine,
Here is the rootkit log.
Hi Admin3k,
"O16 - DPF: {AA299E98-6FB5-409F-99D3-D
Hi Davis,
I'll try your suggestion as well.
Thank you all.
You may also want to empty the contents of %TEMP% directory, as well as temporary internet files /browser cache for rootkit revealer to get more accurate results
you can also try malwarebytes scan in safe mode
finally , if this server hosts critical information, I would honestly suggest to backup critical data & rebuild the system from a clean image , I find this safer in case of similar undocumented rootkit behaviour , no one can tell you for sure what this piece of malware has done to your system & what type of access it could have allowed to your network , I have learnt to better be safe than sorry in such situations :).
I've seen this behavior before...I think it's a false-positive due to some corrupted virus definitions. Please try the following:
1) Run CCleaner again (i know that you've already done that, but we need to erase all junk/corrupted files)
2) Clear out current definitions, check the following on how to do it:
http://service1.symantec.c
3) Download & run Symantec Intelligent Updater to install the latest SEP's definitions
http://definitions.symante
If you tried to download it and got an error like (file not found), this means that they've replaced it with a newer one. Go to this link
http://www.symantec.com/bu
then download the first executable that looks like (20090608-051-v5i32.exe)
4) If you still receive the same pop-up, do the following:
1) Stop SEP (Start > Run > net stop "symantec endpoint protection")
2) Go to www.virustotal.com
3) upload one of the detected file before
4) attach a screenshot of the virus scanning results
Everything I have found points to this: http://www.spywarelib.com/
AND, it is interesting that Symantec's link shows an update today (6/10/2009): http://www.symantec.com/se
BUT; it you don't have either the extra MDM.EXE entries or the WINAPII.EXE listed in your Hijaak This log.
If the updated NORTON still doesn't get it (and I don't think it will), how bout we try Nirsoft's Current Ports ( http://www.nirsoft.net/uti
Ok, no problem. You can continue to the rest of steps.
For point (3): you need to download the latest definition file.
http://definitions.symante
Aslin,
I said that I didn't think the reported IRCBot was techically accurate in your situation; but, CurrentPorts will let you kill the process if you have an IRC open and everything says that you do.
Further, DriverManager will let you disable drivers and ProcessExplorer can also kill processes.
While all of these may be more tedious, they will disclose and let you clobber undetected infestations.
So, if CurrentPorts reveals an IRC, clobber it! If you can then deleted those rogue files, great, we need to figure out what is invoking it. If you can't, the IRC will have immediately restarted and inspecting drivers is the most likely path to finding it.
Its rhetorical and cynical; but, did Symantec do its job in the first place?
Business Accounts
Answer for Membership
by: asllinPosted on 2009-06-07 at 03:48:28ID: 24565969
Here is the log from hijackthis.
xe on.exe es.exe exe t.exe t.exe v.exe appliance\ appmgr.exe .exe ce.exe e appliance\ elementmgr .exe t.exe v\inetinfo .exe v.exe \sqlservr. exe exe appliance\ srvcsurg.e xe t.exe .exe exe exe mssearch.e xe t.exe xe exe t.exe v\w3wp.exe v\w3wp.exe askbarMgr. exe .exe ngr.exe e s.exe S.exe
ternet Explorer\Main,Default_Page _URL = res://shdoclc.dll/softAdmi n.htm ternet Explorer\Main,Start Page = about:blank ternet Explorer\Main,Default_Page _URL = http://go.microsoft.com/fw link/?Link Id=69157 ternet Explorer\Main,Default_Sear ch_URL = http://go.microsoft.com/fw link/?Link Id=54896 ternet Explorer\Main,Search Page = http://go.microsoft.com/fw link/?Link Id=54896 ternet Explorer\Main,Start Page = http://go.microsoft.com/fw link/?Link Id=69157 84B7D6BE0B 3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEH elper.dll 06D7942484 F} - C:\PROGRA~1\SPYBOT~1\SDHel per.dll JPMIG.EXE" /Spoil /RemAdvDef /Migration32 NTLGNT\ImS cInst.exe /SYNC NTLGNT\TIN TSETP.EXE /SYNC NTLGNT\TIN TSETP.EXE /IMEName KRMIG.EXE askbarMgr. exe WTray.exe .exe rt Menu\Programs\Administrati ve Tools\Total Control.msc ngr.exe 0401C60850 1} - C:\Program Files\Java\jre1.5.0_04\bin \npjpi150_ 04.dll 0401C60850 1} - C:\Program Files\Java\jre1.5.0_04\bin \npjpi150_ 04.dll FF36D6C704 0} - C:\Program Files\WinHTTrack\WinHTTrac kIEBar.dll FF36D6C704 0} - C:\Program Files\WinHTTrack\WinHTTrac kIEBar.dll C9C571A826 3} - C:\PROGRA~1\MI1933~1\OFFIC E11\REFIEB AR.DLL 8CAB36FD2A 2} - C:\PROGRA~1\SPYBOT~1\SDHel per.dll 8CAB36FD2A 2} - C:\PROGRA~1\SPYBOT~1\SDHel per.dll E3A5CAA8CD 8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fw link/?link id=58813 7C580BBF70 0} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fw link/?link id=39204 960A1ED54C 9} (WebWatch Class) - http://63.80.250.149:888/C tl/WinWebP ush.cab 000F8773BF 0} (DLC Class) - https://transfers.ds.micro soft.com/F TM/Transfe rSource/ gr TransferCt rl.cab 30D749F486 4} (kasRmtHlp Class) - http://mgt.nowmynetworks.c om/inc/kax Remote.dll 4455354000 0} (Shockwave Flash Object) - http://fpdownload2.macrome dia.com/ge t/shockwav e/cabs/fla sh/ swflash .cab 060082AA75 C} (GpcContainer Class) - https://vncssl.webex.com/c lient/wbs2 5-vzbprodi ns/webex/ i eatgpc.cab A0ADF03058 B} (JuniperSetupSP1 Control) - https://mailgate.asat.com/ dana-cache d/setup/ Ju niperSetup SP1.cab cpip\Param eters: Domain = Doraemon.Net : DomainName = Doraemon.Net cpip\..\{9 A63DCCD-6D AE-4A84-85 4A-48BD905 14152}: NameServer = 192.168.1.250 r) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe ice) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe ~1\NT\besa kalert.exe ce.exe WService.e xe P~1\LUCOMS ~1.EXE exe .exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:47:19 AM, on 6/7/2009
Platform: Windows 2003 SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\Program Files\Symantec AntiVirus\Smc.exe
C:\WINDOWS\System32\svchos
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spools
C:\WINDOWS\system32\server
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\Program Files\Prevx\prevx.exe
C:\WINDOWS\system32\Dfssvc
C:\Program Files\Executive Software\Diskeeper\DkServi
C:\WINDOWS\System32\dns.ex
C:\WINDOWS\system32\server
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\inetsr
C:\WINDOWS\System32\ismser
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn
C:\WINDOWS\system32\ntfrs.
C:\WINDOWS\system32\server
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\System32\svchos
C:\Program Files\RealVNC\VNC4\WinVNC4
C:\Program Files\Exchsrvr\bin\exmgmt.
C:\Program Files\Exchsrvr\bin\mad.exe
C:\WINDOWS\system32\mqsvc.
C:\Program Files\Common Files\System\MSSearch\Bin\
C:\WINDOWS\System32\svchos
C:\Program Files\Exchsrvr\bin\store.e
C:\Program Files\Exchsrvr\bin\emsmta.
C:\WINDOWS\System32\svchos
c:\windows\system32\inetsr
c:\windows\system32\inetsr
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec AntiVirus\SmcGui.exe
C:\Program Files\Prevx\prevx.exe
C:\Program Files\VERITAS\VxUpdate\VxT
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
C:\WINDOWS\system32\mmc.ex
C:\Program Files\Trend Micro\HijackThis\HijackThi
C:\Program Files\Symantec AntiVirus\SymCorpUI.exe
C:\Program Files\Executive Software\Diskeeper\DfrgNTF
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-2
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IM
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PI
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TI
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TI
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IME
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxT
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AA
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Total Control.lnk = C:\Documents and Settings\Administrator\Sta
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlma
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-A
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-A
O9 - Extra button: ???? - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-5
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-5
O15 - ESC Trusted Zone: http://runonce.msn.com
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {7876E4A5-78B7-4020-B08F-C
O16 - DPF: {82774781-8F4E-11D1-AB1C-0
O16 - DPF: {AA299E98-6FB5-409F-99D3-D
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CCS\Services\T
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerato
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaServ
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Backup Exec Alerts Bridge (besakalert) - VERITAS Software Corporation - C:\PROGRA~1\VERITAS\BACKUP
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkServi
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AA
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\SNAC.EXE
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: VPRemote Install Bootstrap Service (VPREMOTE) - Symantec Corporation - C:\TEMP\Clt-Inst\vpremote.
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4
--
End of file - 8812 bytes