Hello all,
I'm having an issue with a laptop at a client that I have so far been unsuccessful at resolving. Symantec Antivirus is reporting an infection on the laptop during it's quick scan that occurs immediately after logon. I've already ran scans using SAV, Ad-aware, and Spybot with the system booted in normal mode as well as in safe mode, emptied the contents of all Temp Internet Files, Cookies, all user temp directories, c:\temp, and c:\windows\temp. I've also removed a couple questionable (I don't remember what they were now) entries that were in HKLM\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run and HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Run. I've looked for them, but can't find any of the files referenced in the SAV log. Regardless of all this, however, the scan still finds and alerts of the infection within a couple minutes of logging on. The laptop is running WinXP Pro SP2. I'm hoping to not have to format and rebuild this particular laptop from scratch, so I'm hoping someone out there sees something I don't.
Here is the contents of the SAV threat log (minus irrelevant info):
Risk Action Count Filename Risk Type Original Location Status Current Location Action Description
Trojan Horse Quarantined 2 x334fdws.exe File C:\WINDOWS\ Infected Quarantine The file was quarantined successfully.
Trojan Horse Quarantined 2 ntfsx.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected Quarantine The file was quarantined successfully.
Infostealer Cleaned by deletion 2 all.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Infostealer Cleaned by deletion 1 vidr.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Trojan Horse Quarantined 2 x334fdws.exe File C:\WINDOWS\ Infected Quarantine The file was quarantined successfully.
Trojan Horse Quarantined 2 ntfsx.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected Quarantine The file was quarantined successfully.
Infostealer Cleaned by deletion 2 all.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Infostealer Cleaned by deletion 1 vidr.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Trojan Horse Quarantined 2 x334fdws.exe File C:\WINDOWS\ Infected Quarantine The file was quarantined successfully.
Trojan Horse Quarantined 1 ntfsx.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected Quarantine The file was quarantined successfully.
Infostealer Cleaned by deletion 1 all.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Infostealer Cleaned by deletion 1 vidr.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Trojan Horse Quarantined 2 x334fdws.exe File C:\WINDOWS\ Infected Quarantine The file was quarantined successfully.
Trojan Horse Quarantined 2 ntfsx.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected Quarantine The file was quarantined successfully.
Infostealer Cleaned by deletion 2 all.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Infostealer Cleaned by deletion 1 vidr.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Trojan Horse Quarantined 2 x334fdws.exe File C:\WINDOWS\ Infected Quarantine The file was quarantined successfully.
Trojan Horse Quarantined 2 ntfsx.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected Quarantine The file was quarantined successfully.
Infostealer Cleaned by deletion 2 all.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Infostealer Cleaned by deletion 2 vidr.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Trojan Horse Quarantined 2 x334fdws.exe File C:\WINDOWS\ Infected Quarantine The file was quarantined successfully.
Trojan Horse Quarantined 2 ntfsx.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected Quarantine The file was quarantined successfully.
Infostealer Cleaned by deletion 2 all.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Infostealer Cleaned by deletion 2 vidr.exe File C:\WINDOWS\system32\driver
s\ssl\06\ Infected C:\WINDOWS\system32\driver
s\ssl\06\
Here is my HiJackThis log:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:07:17 AM, on 5/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Webroot\Enterprise\S
py Sweeper\commagent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\driver
s\ssl\06\r
ar.exe
C:\Program Files\Webroot\Enterprise\S
py Sweeper\spysweeper.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Enterprise\S
py Sweeper\SSU.EXE
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe
C:\Program Files\Java\jre1.5.0_11\bin
\jusched.e
xe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTra
y.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.
exe
C:\Program Files\Webroot\Enterprise\S
py Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Handspring\HOTSYNC.E
XE
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EX
E
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EX
E
\sdbsrv03\ABD\Ultra-Staff\
Executable
\ABDUltraS
taff.exe
C:\Documents and Settings\missym\Desktop\Hi
JackThis_v
2.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
84B7D6BE0B
3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.d
ll
O4 - HKLM\..\Run: [SigmaTel StacMon] "C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\D
VDLauncher
.exe"
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
ync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin
\jusched.e
xe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
y.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.
exe"
O4 - HKLM\..\Run: [SpySweeperEnterprise] "C:\Program Files\Webroot\Enterprise\S
py Sweeper\\SpySweeperUI.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateMana
ger.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Handspring\HOTSYNC.E
XE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2
\OFFICE11\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_11\bin
\npjpi150_
11.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_11\bin
\npjpi150_
11.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {493ACF15-5CD9-4474-82A6-9
1670C3DD66
E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedInContactFinderControl.cabO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1152116498245O17 - HKLM\System\CCS\Services\T
cpip\Param
eters: Domain = sdb.local
O17 - HKLM\Software\..\Telephony
: DomainName = sdb.local
O17 - HKLM\System\CS1\Services\T
cpip\Param
eters: Domain = sdb.local
O17 - HKLM\System\CS2\Services\T
cpip\Param
eters: Domain = sdb.local
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-0
0A0C90312E
1} - C:\WINDOWS\system32\browse
ui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3
078302C203
0} - C:\WINDOWS\system32\browse
ui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEU
P~1\LUCOMS
~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Webroot CommAgent Service (WebrootCommAgentService) - Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\S
py Sweeper\commagent.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService)
- Webroot Software, Inc. - C:\Program Files\Webroot\Enterprise\S
py Sweeper\spysweeper.exe
O23 - Service: Windows Licence Managements - Unknown owner - C:\WINDOWS\licences.exe
--
End of file - 7508 bytes
Thank you for any help received!!!
- Brian