Hi Experts
I've been asked to clean up an infected laptop and am having problems.
It is running XP SP2 with IE7 & Firefox, and was exhibiting signs of infection with IE Antivirus 2009.
I have run Spybot (with manual updates), AdAware 2007 and Winsock fix to remove all infections but it it still partially resident. I have not yet tried to isolate a specific fix for Antivirus 2009 as I am more interested in understanding in what form and where the infection resides in the windows configuration.
Specifically, the IE Antivirus 2009 screen appears intermittently when clicking through to random search page results, and I am unable to browse
www.lavasoft.com,
www.safer-networking.com, and other "anti-malware" sites. I can browse many other sites successfully, and can browse lavasoft.com via its IP address but not via DNS. Additionally, Spybot and Adaware cannot download updates.
The hosts file was untainted, and adding the IP address for lavasoft.com did not resolve the problem. I can also ping
www.lavasoft.com, and my DNS lookup resolves to 192.168.100.1 (Netgear DG834N).
My own PCs are unaffected by any networking or DNS issues.
Both Sysinternals AUTORUNS and my HIJACKTHIS log do not appear to yield any suspect startup entries.
I would like to understand where in the chain of DNS processing the infection occurs. If I can ping, view and download information and files from lavasoft and my Hosts file is unchanged, where else can the DNS resolution be affected (there are no BHOs involved and Firefox returns a "failed to connect" message too, so it doesn't appear to be an IE issue).
Various infections place entries in the registry (e.g in HKEY_CLASSES_ROOT). What part does this play in DNS resolution/redirection?
HIJACK log is below.
Regards
Ade
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:32:37, on 18/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\Ati2ev
xx.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\system32\acs.ex
e
C:\PROGRA~1\AVG\AVG8\avgwd
svc.exe
C:\Program Files\TOSHIBA\ConfigFree\C
FSvcs.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\AVG\AVG8\avgrs
x.exe
C:\PROGRA~1\AVG\AVG8\avgem
c.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\TOSHIBA\Tvs\TvsTray.
exe
C:\WINDOWS\system32\TPSMai
n.exe
C:\Program Files\TOSHIBA\ConfigFree\N
DSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
C:\Program Files\Windows Live\Family Safety\fssui.exe
C:\Program Files\Lexmark 3400 Series\lxcymon.exe
C:\Program Files\Lexmark 3400 Series\ezprint.exe
C:\PROGRA~1\AVG\AVG8\avgtr
ay.exe
C:\Program Files\TOSHIBA\TOSCDSPD\tos
cdspd.exe
C:\Program Files\BitComet\BitComet.ex
e
C:\Program Files\Common Files\Ahead\Lib\NMBgMonito
r.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\TPSBat
tM.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexSto
reSvr.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexing
Service.ex
e
C:\WINDOWS\system32\lxcyco
ms.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Lavasoft\Ad-Aware\aa
wservice.e
xe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
C:\WINDOWS\system32\wuaucl
t.exe
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://www.sky.comR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://google.atcomet.com/b/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Internet Explorer Provided By Sky Broadband
O1 - Hosts: 209.87.179.221
www.lavasoft.comO2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5
B79BFDFEA6
0} - C:\Program Files\BitComet\tools\BitCo
metBHO_1.2
.6.26.dll
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d
13f3d2976a
c} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O3 - Toolbar: Lexmark Toolbar - {1017A80C-6F09-4548-A84D-E
DD6AC9525F
0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
09027A5CD4
F} - c:\program files\google\googletoolbar
1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-7
9A187E2698
E} - C:\PROGRA~1\AVG\AVG8\AVGTO
O~1.DLL
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynT
PLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
PEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.
exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fssui.exe" -autorun
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.
exe
O4 - HKLM\..\Run: [lxcymon.exe] "C:\Program Files\Lexmark 3400 Series\lxcymon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 3400 Series\ezprint.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [LXCYCATS] rundll32 C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\LXC
Ytime.dll,
_RunDLLEnt
ry@16
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtr
ay.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\tos
cdspd.exe
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.ex
e" /tray
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-
4d9f-84C7-
88D8A56B10
AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonito
r.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
Notifier\G
oogleToolb
arNotifier
.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'Default user')
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.ex
e/AddLink.
htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.ex
e/AddVideo
.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.ex
e/AddAllLi
nk.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_04\bin
\npjpi150_
04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.5.0_04\bin
\npjpi150_
04.dll
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-0
1E4AD8016F
6} -
http://www.sky.com (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
C9C571A826
3} - C:\PROGRA~1\MICROS~2\OFFIC
E11\REFIEB
AR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C
1E3DC1AF43
A} - res://C:\Program Files\BitComet\tools\BitCo
metBHO_1.2
.6.26.dll/
206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprov
au.dll
O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212699456134O16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1212699446741O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
4455354000
0} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-F
BDDE494F8D
1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aa
wservice.e
xe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.ex
e
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.
exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2ev
xx.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgem
c.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwd
svc.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\C
FSvcs.exe
O23 - Service: lxcy_device - - C:\WINDOWS\system32\lxcyco
ms.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexing
Service.ex
e
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
--
End of file - 9390 bytes