Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Possible Downloader time bomb problem  (Read 4376 times)

0 Members and 1 Guest are viewing this topic.

dhinds

    Topic Starter


    Beginner

  • My Katrina Hat
    Possible Downloader time bomb problem
    « on: April 05, 2007, 07:00:19 PM »
    Hi everyone, I am new to this forum so hello. I think I have the Downloader.Trojan on my computer and have run both Norton and AVG to try and seek it out, no luck. I got this message in AVG

    Warning: Action failed for registry value HKLM\SOFTWARE\Classes\Component Categories\{56FFCC30-D398-11D0-B2AE-00A0C908FA49}:409: creating registry value....
                Access is denied.  (5)

    Does any one know enough about the registry to tell me what this is. I don't like changing the registry so I can help it I had rather find it in the folder hierachie If I can and zap it. Thanks in advance if you have any ideas. D
    Memories fade with time, replenish them with new experiences.

    patio

    • Moderator


    • Genius
    • Maud' Dib
    • Thanked: 1769
      • Yes
    • Experience: Beginner
    • OS: Windows 7
    Re: Possible Downloader time bomb problem
    « Reply #1 on: April 05, 2007, 08:50:16 PM »
    The message means AVG was not allowed access to that portion of the registry.
    This doesn't neccessarily mean you are infected...why do you suspect this ? ?

    Can you list any other protection programs you have ? ?
    " Anyone who goes to a psychiatrist should have his head examined. "

    dhinds

      Topic Starter


      Beginner

    • My Katrina Hat
      Re: Possible Downloader time bomb problem
      « Reply #2 on: April 06, 2007, 08:09:39 AM »
      About a week ago I got a pop up message from Norton saying that Downloader had been detected and it couldn't fix it. I took evasive action but probably didn't stop its' download. Nothing it happening with my computer "yet" but I feel like it is a time bomb waiting to explode. Perhaps it is just paranoia because I am working on an important project. Thanks
      Memories fade with time, replenish them with new experiences.

      unlovedwarrior



        Guru

      • someday this name will be known
      • Thanked: 13
        Re: Possible Downloader time bomb problem
        « Reply #3 on: April 06, 2007, 08:18:14 AM »
        download and install avg antispyware free (if you dont already) and spybot search and destroy

        update them turn system restore off and reboot into safe mode do the scans and post the avg antspyware log here

        also get hijackthis and do a scan and save log and post the log here (the log can take several posts)


        unlovedwarrior

        dhinds

          Topic Starter


          Beginner

        • My Katrina Hat
          Re: Possible Downloader time bomb problem
          « Reply #4 on: April 10, 2007, 12:46:55 PM »
          Sorry for the delay, had to go out of town and get hijackthis


          Logfile of HijackThis v1.97.7
          Scan saved at 1:42:48 PM, on 4/10/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16414)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
          C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
          C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
          C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
          C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\WINDOWS\System32\CTsvcCDA.exe
          C:\WINDOWS\System32\GEARSec.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
          C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
          C:\Program Files\Norton Ghost\Agent\VProSvc.exe
          C:\WINDOWS\System32\nvsvc32.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\MsPMSPSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\System32\DSentry.exe
          C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Norton Ghost\Agent\GhostTray.exe
          C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\System32\HPZipm12.exe
          C:\WINDOWS\System32\dllhost.exe
          C:\WINDOWS\System32\vssvc.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\DOCUME~1\Dennis\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
          C:\Program Files\Messenger\msmsgs.exe

          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.dcc.edu"); (C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\m5cwi299.slt\prefs.js)
          N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Dennis\Application Data\Mozilla\Profiles\default\m5cwi299.slt\prefs.js)
          O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
          O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
          O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
          O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
          O2 - BHO: (no name) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
          O2 - BHO: (no name) - {C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} - C:\Program Files\NavExcel\NavHelper\v2.0.4c\NHelper.dll (file missing)
          O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
          O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
          O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
          O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
          O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
          O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
          O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
          O4 - HKCU\..\Run: [SB Audigy 2 Startup Menu] /L:ENG
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
          O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
          O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
          O9 - Extra button: Research (HKLM)
          O9 - Extra button: Real.com (HKLM)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 (HKLM)
          O9 - Extra button: Messenger (HKLM)
          O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
          O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll
          O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll
          O10 - Unknown file in Winsock LSP: c:\program files\google\google desktop search\googledesktopnetwork1.dll
          O11 - Options group: [INTERNATIONAL] International*
          O12 - Plugin for .mts: C:\Program Files\MetaCreations\MetaStream\npmetastream.dll
          O15 - Trusted Zone: http://faculty-web.dcc.edu
          O15 - Trusted Zone: http://www.dcc.edu
          O15 - Trusted Zone: http://*.fiberartsstudio.com
          O15 - Trusted Zone: http://www.macromedia.com

          Memories fade with time, replenish them with new experiences.

          patio

          • Moderator


          • Genius
          • Maud' Dib
          • Thanked: 1769
            • Yes
          • Experience: Beginner
          • OS: Windows 7
          Re: Possible Downloader time bomb problem
          « Reply #5 on: April 11, 2007, 03:28:46 AM »
          1) This is not a complete log...it may take a few posts to get it all due to the Forum limitations on post length...this is normal.

          2) Update and run all your scans once more

          3) Re- install Hijack this into it's own directory ...name it HJ1 or something you choose. It shouldn't be run from a Temp directory.

          4) Update and run all your scans once more

          5) Answer
          Quote
          Can you list any other protection programs you have ? ?
          this
          " Anyone who goes to a psychiatrist should have his head examined. "

          unlovedwarrior



            Guru

          • someday this name will be known
          • Thanked: 13
            Re: Possible Downloader time bomb problem
            « Reply #6 on: April 11, 2007, 08:16:57 AM »
            the log will go to 23 itll take two or more post..

            GX1_Man

            • Guest
            Re: Possible Downloader time bomb problem
            « Reply #7 on: April 13, 2007, 06:39:19 AM »
            I think the virus has done something to the original poster.  :o

            patio

            • Moderator


            • Genius
            • Maud' Dib
            • Thanked: 1769
              • Yes
            • Experience: Beginner
            • OS: Windows 7
            Re: Possible Downloader time bomb problem
            « Reply #8 on: April 13, 2007, 09:23:48 AM »
            At least it wasn't the aliens this time... ;D
            " Anyone who goes to a psychiatrist should have his head examined. "

            oddjob



              Hopeful

              Thanked: 4
              • Experience: Beginner
              • OS: Windows 7
              Re: Possible Downloader time bomb problem
              « Reply #9 on: April 23, 2007, 07:16:49 AM »
              Maybe due to the use of an out of date version of HJT and the fact that it's in a temporary location, hmm...??


              OJ