Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Possibly Conficker, logs included  (Read 3974 times)

0 Members and 1 Guest are viewing this topic.

DavidG

    Topic Starter


    Greenhorn

    Possibly Conficker, logs included
    « on: June 26, 2009, 09:30:14 AM »
    Ok...a couple days ago I had to format my C and reinstall windows xp pro. One of the first things I did was install windows update and get sp2.  Then reinstalled AVG Malwarebytes and Opera. Last night I discovered I needed to get the .net frame for another program I run.
     I cant get to any part of the Microsoft domain using either Opera or IE6.
    Installing IE8 via yahoo failed.
    Uninstalling AVG doesnt fix it. There are no blocked sites listed anywhere I can find in Opera or IE.
    I can go anywhere else I want.
    Others reach the site fine and I can reach it fine on my laptop, so its not a router issue I guess.
    There is no SAS log as I cant get to the site to download it.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 1:34:40 PM, on 6/26/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
    C:\PROGRA~1\AVG\AVG8\avgemc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\D-Link\AirPlus XtremeG DWL-G520\AirPlusCFG.exe
    C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
    C:\WINDOWS\system32\svchost.exe
    D:\Program Files\Opera\Opera.exe
    C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpctr.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Trend Micro\HijackThis\Sniper.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [D-Link AirPlus XtremeG DWL-G520] C:\Program Files\D-Link\AirPlus XtremeG DWL-G520\AirPlusCFG.exe
    O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKUS\S-1-5-21-1214440339-1604221776-725345543-1003\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User '?')
    O4 - HKUS\S-1-5-21-1214440339-1604221776-725345543-1003\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet (User '?')
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1245972850194
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
    O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

    --
    End of file - 5238 bytes

    ===========================================
    Malwarebytes' Anti-Malware 1.38
    Database version: 2297
    Windows 5.1.2600 Service Pack 2

    6/26/2009 2:58:37 PM
    mbam-log-2009-06-26 (14-58-37).txt

    Scan type: Full Scan (C:\|D:\|E:\|)
    Objects scanned: 130513
    Time elapsed: 1 hour(s), 7 minute(s), 25 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 5

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\WINDOWS\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\documents and settings\Administrator\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    c:\documents and settings\DavidG\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    Thank you for you help





    paudashlake



      Hopeful

      Thanked: 6
      • Experience: Experienced
      • OS: Windows 7
      Re: Possibly Conficker, logs included
      « Reply #1 on: June 26, 2009, 09:41:07 PM »
      Are you sure you reinstalled or just recopied the files?  Some name brand computers have either a copy windows files over setting or a destructive setting.  You may not have set it to  format the hdd.
      Hinkle Finkle Dinkle Doo.  AMEN!! 


      Karnac



        Specialist

        Thanked: 211
        Re: Possibly Conficker, logs included
        « Reply #2 on: June 26, 2009, 09:46:22 PM »
        Paudash, he has Virut...he has to reformat/reinstall.


        Never argue with a stupid person, they'll drag you down to their level and beat you with experience.

        DavidG

          Topic Starter


          Greenhorn

          Re: Possibly Conficker, logs included
          « Reply #3 on: June 26, 2009, 09:48:14 PM »
          Its not a brand name, I built it from parts. It was fully formatted, not the quick version either.
          While Ive been waiting, I used the self help and searched the hjt log. It doesnt show any issues. It doesnt seem to notice that my windows firewall is in fact turned on. I can get to microsoft sites now after scanning the drives multiple times, but its still obvious something is wrong.

          Karnac



            Specialist

            Thanked: 211
            Re: Possibly Conficker, logs included
            « Reply #4 on: June 26, 2009, 09:57:09 PM »
            David, you have a variant of virut.

            C:\WINDOWS\system32\reader_s.exe (Trojan.Agent)


            You can search Virut on this forum, and you'll see evilfantasy recommends wiping the hard drive and reinstall XP.

            You cannot remove this malware, it replicates as quickly as you can remove it.

            Evilfantasy will confirm this for you.


            Never argue with a stupid person, they'll drag you down to their level and beat you with experience.

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: Possibly Conficker, logs included
            « Reply #5 on: June 26, 2009, 11:15:35 PM »
            Good eye Karnac. ;)

            The logs show that you are infected by an infection called Virut or Sality. Virut/Sality is a virus that infects all executable files and screensavers. Virut also opens a back door providing the attacker with unauthorized remote access to the infected computer. Definition: Polymorphic virus.

            There is no way to cure this infection. Your only option is to perform a full reformat. Do NOT attempt a repair install. Trying to fix this infection will only leave the computer unusable. See Virut on the Rise and Virut and other File infectors - Throwing in the Towel? for more information. 

            Note that if you decide to try and clean this you must be extremely careful on what is backed up as these new infections can get into many different file extensions ( DLL, EXE, SCR, HTM, HTML, MP3, AVI, WMV, PDF.....etc). A complete reformat and reinstall is highly suggested! Avoid backing up compressed files (zip/cab/rar.....etc). Virut can also penetrate compressed files that have .exe or .scr inside them.

            Backing up files before formatting

            If you backup any files they should be scanned from a clean properly protected PC before restoring. Also be careful what scanner is used as some are very poor at detecting and even worse at protecting from this infection. In fact due to the nature of these new infections there are probably no tools that will properly protect you from the infection. Be very selective and only backup files you can not replace like text documents and personal photos.

            Do not back up to another machine! It will likely become infected by Virut. Burn to DVD/CD, a flash drive or to an external drive which has nothing else on it and which you can format should it become infected from the backups.

            I suggest running at least 3 of the below scanners on the backup files. Run the first scan then reboot before running the second then reboot after the second before running the third.
             
            -) Dr.Web CureIt!
            -) AVG Win32/Virut Removal Tool
            -) Symantwc W32.Virut Removal Tool
            -) McAfee Avert Stinger
            -) Microsoft Windows Malicious Software Removal Tool

            If you do not know how to perform a fresh install, use this website -> http://www.windowsreinstall.com/

            Very important, do the following immediately or as soon as possible!

            If you have done any online transactions, call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts and/or change all of your account numbers.
             
            From a clean computer change all of your online passwords including for email, banks, financial accounts, PayPal, eBay, online credit card companies and any online forums or groups you belong to etc.

            DO NOT change passwords or do any transactions while using the infected computer. The attacker will get the new passwords and transaction information.