|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
AAngelo
Cadet

 Joined: Jul 08, 2004 Posts: 6 Location: Italy
|
Posted: Sat Jul 10, 2004 9:14 am Post subject: IE HOME PAGE CHANGED |
|
|
Hi all!
My configuration:
OS: Microsoft Windows XP Professional Version 2002, Service Pack 1
Firewall: now turned to Sygate Personal Firewall (I used ZoneAlarm, previously)
Periodically scan with: Ad-Aware, SpyBot; updated every day.
Antivirus: Norton Antivirus (periodically updated).
Since a few days, the home page of Internet Explorer (ver.6.0) is changed to:
res://ABCDE.dll/index.html#96676
where ABCDE is a 5 characters variable (random, I suppose):
the first time was:
res://ftndn.dll/index.html#96676
now, after some AdAware cleaning, is still:
res://esrnr.dll/index.html#96676
At every PC startup, I scan with SpyBot then AdAware but their cleaning is useless: they seems to clean everithing, but the next scan I make shows again similar malware.
________
Each time I attempt to start IE, Sygate Firewall block it.
IE attempts to connect to www.v61.com .
Thi is the header of the resulting Sygate log:
File Version : 6.00.2800.1106 (xpsp1.020828-1920)
File Description : Internet Explorer (iexplore.exe)
File Path : C:\Programmi\Internet Explorer\iexplore.exe
Process ID : 0xA94 (Heximal) 2708 (Decimal)
Connection origin : local initiated
Protocol : TCP
Local Address : 1.255.161.189
Local Port : 1106
Remote Name : www.v61.com
Remote Address : 209.66.122.49
Remote Port : 80 (HTTP - World Wide Web)
________
Attached is the scan log of HiJackThis and AdAware.
Please, suggest me what to clean: I am not able to identify all items.
THANKS![/code]
| Description: |
|
 Download |
| Filename: |
AD_AWARE_LOGFILE_20040710H1030.TXT |
| Filesize: |
23.97 KB |
| Downloaded: |
45 Time(s) |
| Description: |
|
 Download |
| Filename: |
HIJACKTHIS_startuplist_20040710H1050.txt |
| Filesize: |
14.04 KB |
| Downloaded: |
62 Time(s) |
_________________ Antonio
|
|
| Back to top |
|
 |
Yellowhammer
Site Moderator Microsoft MVP
 Joined: Jan 30, 2004 Posts: 18022
|
Posted: Sat Jul 10, 2004 5:37 pm Post subject: |
|
|
Please just post a hijackthis log. That should provide enough information to do the fix. _________________ Yellowhammer
MS-MVP Security 2005/2006
How to prevent Reinfection
|
|
| Back to top |
|
 |
AAngelo
Cadet

 Joined: Jul 08, 2004 Posts: 6 Location: Italy
|
Posted: Wed Jul 21, 2004 7:33 am Post subject: D3XQ.EXE |
|
|
Hi!
My configuration:
OS: Microsoft Windows XP Professional Version 2002, Service Pack 1
As suggested by site http://ralphcaddell.com/pchelp/spyware.htm, I installed the following:
- IE-SpyAd
- SpyWare Blaster
- Trojan Hunter
- Norton Antivirus
- Sygate Personal Firewall
In addition:
- Administrator user has a non-easy password
- Currently used user profiles are not Administrators
Almost daily I scan deeply (and clean) with AdAware (always after an update), then with SpyBot.
At every startup I get the following warning by Sygate Firewall:
07/21/2004 08:40:25 Executable File Change
Denied Major
Outgoing TCP 38.117.144.162 00-09-44-3B-60-38 1.255.161.189 00-0C-6E-A2-7F-6E
C:\WINDOWS\d3xq.exe Pap TAKOMPUTER Normal 1 07/21/2004 08:40:25 07/21/2004 08:40:25
This is my last HijackThis log scan:
| Code: |
Logfile of HijackThis v1.97.7
Scan saved at 9.11.32, on 21/07/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
C:\Programmi\File comuni\Symantec Shared\ccApp.exe
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\WINDOWS\d3xq.exe
C:\Programmi\TrojanHunter 3.9\THGuard.exe
C:\Video\Common\Bin\WinCinemaMgr.exe
C:\Programmi\Acrobat Writer 5.0\Distillr\AcroTray.exe
C:\WINDOWS\system32\ntvdm.exe
C:\Programmi\lotus\organize\easyclip.exe
C:\PROGRA~1\OPLIMIT\ocrawr32.exe
C:\WINDOWS\explorer.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\esrnr.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://esrnr.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://esrnr.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\esrnr.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://esrnr.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\esrnr.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\programmi\Acrobat Writer 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {8EF1A389-7342-F785-A50A-A3C78BA42012} - C:\WINDOWS\system32\apibq32.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmi\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIPTA] C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Smapp] C:\Programmi\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ccApp] C:\Programmi\File comuni\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programmi\Philips\Digital Media Manager\java\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [d3xq.exe] C:\WINDOWS\d3xq.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [THGuard] "C:\Programmi\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - HKLM\..\RunOnce: [sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
O4 - HKLM\..\RunOnce: [mfcyp.exe] C:\WINDOWS\mfcyp.exe
O4 - HKLM\..\RunOnce: [netrt.exe] C:\WINDOWS\netrt.exe
O4 - HKLM\..\RunOnce: [ntww.exe] C:\WINDOWS\ntww.exe
O4 - HKLM\..\RunOnce: [ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
O4 - HKLM\..\RunOnce: [ntbw32.exe] C:\WINDOWS\ntbw32.exe
O4 - HKLM\..\RunOnce: [crbn32.exe] C:\WINDOWS\system32\crbn32.exe
O4 - HKLM\..\RunOnce: [sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
O4 - HKLM\..\RunOnce: [d3dl.exe] C:\WINDOWS\d3dl.exe
O4 - HKLM\..\RunOnce: [mfcod.exe] C:\WINDOWS\mfcod.exe
O4 - HKLM\..\RunOnce: [apiel.exe] C:\WINDOWS\system32\apiel.exe
O4 - HKLM\..\RunOnce: [ntxo32.exe] C:\WINDOWS\ntxo32.exe
O4 - HKLM\..\RunOnce: [atlag.exe] C:\WINDOWS\atlag.exe
O4 - HKLM\..\RunOnce: [mszo32.exe] C:\WINDOWS\system32\mszo32.exe
O4 - HKLM\..\RunOnce: [d3qk.exe] C:\WINDOWS\d3qk.exe
O4 - HKLM\..\RunOnce: [javahd32.exe] C:\WINDOWS\system32\javahd32.exe
O4 - HKLM\..\RunOnce: [appds32.exe] C:\WINDOWS\appds32.exe
O4 - HKLM\..\RunOnce: [apipp.exe] C:\WINDOWS\system32\apipp.exe
O4 - HKLM\..\RunOnce: [mfcnn.exe] C:\WINDOWS\mfcnn.exe
O4 - HKLM\..\RunOnce: [mfckl.exe] C:\WINDOWS\system32\mfckl.exe
O4 - HKLM\..\RunOnce: [netlc.exe] C:\WINDOWS\system32\netlc.exe
O4 - HKLM\..\RunOnce: [atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
O4 - HKLM\..\RunOnce: [addtm32.exe] C:\WINDOWS\system32\addtm32.exe
O4 - HKLM\..\RunOnce: [crad.exe] C:\WINDOWS\crad.exe
O4 - HKLM\..\RunOnce: [javapt.exe] C:\WINDOWS\system32\javapt.exe
O4 - HKLM\..\RunOnce: [javauu32.exe] C:\WINDOWS\javauu32.exe
O4 - HKLM\..\RunOnce: [d3yp.exe] C:\WINDOWS\system32\d3yp.exe
O4 - HKLM\..\RunOnce: [crwo32.exe] C:\WINDOWS\crwo32.exe
O4 - HKLM\..\RunOnce: [ieim32.exe] C:\WINDOWS\system32\ieim32.exe
O4 - HKLM\..\RunOnce: [sysyu.exe] C:\WINDOWS\sysyu.exe
O4 - HKLM\..\RunOnce: [mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
O4 - HKLM\..\RunOnce: [atlfg.exe] C:\WINDOWS\system32\atlfg.exe
O4 - HKLM\..\RunOnce: [winvr32.exe] C:\WINDOWS\winvr32.exe
O4 - HKLM\..\RunOnce: [iebp.exe] C:\WINDOWS\system32\iebp.exe
O4 - HKLM\..\RunOnce: [ipyn.exe] C:\WINDOWS\ipyn.exe
O4 - HKLM\..\RunOnce: [mspm.exe] C:\WINDOWS\mspm.exe
O4 - HKLM\..\RunOnce: [javaee.exe] C:\WINDOWS\system32\javaee.exe
O4 - HKLM\..\RunOnce: [addfm32.exe] C:\WINDOWS\addfm32.exe
O4 - HKLM\..\RunOnce: [addrs.exe] C:\WINDOWS\addrs.exe
O4 - HKLM\..\RunOnce: [crfy.exe] C:\WINDOWS\system32\crfy.exe
O4 - HKLM\..\RunOnce: [crrd.exe] C:\WINDOWS\crrd.exe
O4 - HKLM\..\RunOnce: [apptr32.exe] C:\WINDOWS\system32\apptr32.exe
O4 - HKLM\..\RunOnce: [d3wk.exe] C:\WINDOWS\d3wk.exe
O4 - HKLM\..\RunOnce: [apilk32.exe] C:\WINDOWS\apilk32.exe
O4 - HKLM\..\RunOnce: [iedm.exe] C:\WINDOWS\system32\iedm.exe
O4 - HKLM\..\RunOnce: [javagm.exe] C:\WINDOWS\system32\javagm.exe
O4 - HKLM\..\RunOnce: [ntjw32.exe] C:\WINDOWS\ntjw32.exe
O4 - HKLM\..\RunOnce: [netdo32.exe] C:\WINDOWS\netdo32.exe
O4 - HKLM\..\RunOnce: [sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
O4 - HKLM\..\RunOnce: [sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
O4 - HKLM\..\RunOnce: [addko.exe] C:\WINDOWS\addko.exe
O4 - HKLM\..\RunOnce: [mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
O4 - HKLM\..\RunOnce: [sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
O4 - HKLM\..\RunOnce: [msen.exe] C:\WINDOWS\system32\msen.exe
O4 - HKLM\..\RunOnce: [msug.exe] C:\WINDOWS\msug.exe
O4 - HKLM\..\RunOnce: [crkf32.exe] C:\WINDOWS\crkf32.exe
O4 - HKLM\..\RunOnce: [winqj.exe] C:\WINDOWS\system32\winqj.exe
O4 - HKLM\..\RunOnce: [sysgh32.exe] C:\WINDOWS\sysgh32.exe
O4 - HKLM\..\RunOnce: [d3ud32.exe] C:\WINDOWS\d3ud32.exe
O4 - HKLM\..\RunOnce: [netnm.exe] C:\WINDOWS\system32\netnm.exe
O4 - HKLM\..\RunOnce: [apihs32.exe] C:\WINDOWS\system32\apihs32.exe
O4 - HKLM\..\RunOnce: [addfp.exe] C:\WINDOWS\addfp.exe
O4 - HKLM\..\RunOnce: [sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
O4 - HKLM\..\RunOnce: [crpn32.exe] C:\WINDOWS\system32\crpn32.exe
O4 - HKLM\..\RunOnce: [netae.exe] C:\WINDOWS\netae.exe
O4 - HKLM\..\RunOnce: [iewb.exe] C:\WINDOWS\system32\iewb.exe
O4 - HKLM\..\RunOnce: [addkz32.exe] C:\WINDOWS\system32\addkz32.exe
O4 - HKLM\..\RunOnce: [ipdv.exe] C:\WINDOWS\ipdv.exe
O4 - HKLM\..\RunOnce: [ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
O4 - HKLM\..\RunOnce: [winoo.exe] C:\WINDOWS\system32\winoo.exe
O4 - HKLM\..\RunOnce: [ipwi.exe] C:\WINDOWS\system32\ipwi.exe
O4 - HKLM\..\RunOnce: [atlzb.exe] C:\WINDOWS\atlzb.exe
O4 - HKLM\..\RunOnce: [sysss.exe] C:\WINDOWS\sysss.exe
O4 - HKLM\..\RunOnce: [appfh32.exe] C:\WINDOWS\appfh32.exe
O4 - HKLM\..\RunOnce: [sysyh.exe] C:\WINDOWS\sysyh.exe
O4 - HKLM\..\RunOnce: [msge.exe] C:\WINDOWS\system32\msge.exe
O4 - Startup: OCRAWARE.lnk = C:\Programmi\OPLIMIT\OCRAWARE.EXE
O4 - Startup: Lotus Organizer EasyClip.lnk = C:\Programmi\lotus\organize\easyclip.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Video\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmi\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programmi\Acrobat Writer 5.0\Distillr\AcroTray.exe
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Programmi\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1071001562234
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37963.518912037
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab |
How can I solve that? THANKS!!!
Last edited by AAngelo on Wed Jul 21, 2004 3:55 pm, edited 1 time in total |
|
| Back to top |
|
 |
Yellowhammer
Site Moderator Microsoft MVP
 Joined: Jan 30, 2004 Posts: 18022
|
Posted: Wed Jul 21, 2004 9:36 am Post subject: |
|
|
You did not attach the hijackthis log. I need to see it in order to be able to help. In addition please download the attached file. Unzip it and run it. You may have to disable script blocking in Norton Antivirus temporarily in order for the script to run. The program will generate a list of active services. Please copy and paste the contents or upload the txt file.
| Description: |
|
 Download |
| Filename: |
get_active_services_179.zip |
| Filesize: |
678 Bytes |
| Downloaded: |
158 Time(s) |
_________________ Yellowhammer
MS-MVP Security 2005/2006
How to prevent Reinfection
|
|
| Back to top |
|
 |
AAngelo
Cadet

 Joined: Jul 08, 2004 Posts: 6 Location: Italy
|
Posted: Wed Jul 21, 2004 4:03 pm Post subject: |
|
|
Hello!
This is the log of your script:
| Code: | These are the Current Active Services:
AVVISI: Alerter
C:\WINDOWS\System32\svchost.exe -k LocalService
HELPER NETBIOS DI TCP/IP: LmHosts
C:\WINDOWS\System32\svchost.exe -k LocalService
REGISTRO DI SISTEMA REMOTO: RemoteRegistry
C:\WINDOWS\system32\svchost.exe -k LocalService
SERVIZIO DI RILEVAMENTO SSDP: SSDPSRV
C:\WINDOWS\System32\svchost.exe -k LocalService
WEBCLIENT: WebClient
C:\WINDOWS\System32\svchost.exe -k LocalService
ALIAS DOCUMENTATION SERVER: aliasdocserver
"C:\Grafica\Maya 6.0\docs\Wrapper.exe" -s "C:\Grafica\Maya 6.0\docs/Wrapper.conf"
ATI HOTKEY POLLER: Ati HotKey Poller
C:\WINDOWS\System32\Ati2evxx.exe
AUDIO WINDOWS: AudioSrv
C:\WINDOWS\System32\svchost.exe -k netsvcs
SERVIZIO TRASFERIMENTO INTELLIGENTE IN BACKGROUND: BITS
C:\WINDOWS\System32\svchost.exe -k netsvcs
BROWSER DI COMPUTER: Browser
C:\WINDOWS\System32\svchost.exe -k netsvcs
SERVIZI DI CRITTOGRAFIA: CryptSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs
CLIENT DHCP: Dhcp
C:\WINDOWS\System32\svchost.exe -k netsvcs
GESTIONE DISCHI LOGICI: dmserver
C:\WINDOWS\System32\svchost.exe -k netsvcs
SERVIZIO DI SEGNALAZIONE ERRORI: ERSvc
C:\WINDOWS\System32\svchost.exe -k netsvcs
SISTEMA DI EVENTI COM+: EventSystem
C:\WINDOWS\System32\svchost.exe -k netsvcs
COMPATIBILIT DI CAMBIO RAPIDO UTENTE: FastUserSwitchingCompatibility
C:\WINDOWS\System32\svchost.exe -k netsvcs
GUIDA IN LINEA E SUPPORTO TECNICO: helpsvc
C:\WINDOWS\System32\svchost.exe -k netsvcs
SERVER: lanmanserver
C:\WINDOWS\System32\svchost.exe -k netsvcs
WORKSTATION: lanmanworkstation
C:\WINDOWS\System32\svchost.exe -k netsvcs
MESSENGER: Messenger
C:\WINDOWS\System32\svchost.exe -k netsvcs
CONNESSIONI DI RETE: Netman
C:\WINDOWS\System32\svchost.exe -k netsvcs
NLA (NETWORK LOCATION AWARENESS): Nla
C:\WINDOWS\System32\svchost.exe -k netsvcs
UTILIT DI PIANIFICAZIONE: Schedule
C:\WINDOWS\System32\svchost.exe -k netsvcs
ACCESSO SECONDARIO: seclogon
C:\WINDOWS\System32\svchost.exe -k netsvcs
NOTIFICA EVENTI DI SISTEMA: SENS
C:\WINDOWS\system32\svchost.exe -k netsvcs
RILEVAMENTO HARDWARE SHELL: ShellHWDetection
C:\WINDOWS\System32\svchost.exe -k netsvcs
SERVIZI TERMINAL: TermService
C:\WINDOWS\System32\svchost.exe -k netsvcs
TEMI: Themes
C:\WINDOWS\System32\svchost.exe -k netsvcs
MANUTENZIONE COLLEGAMENTI DISTRIBUITI CLIENT: TrkWks
C:\WINDOWS\system32\svchost.exe -k netsvcs
UPLOAD MANAGER: uploadmgr
C:\WINDOWS\System32\svchost.exe -k netsvcs
ORA DI WINDOWS: W32Time
C:\WINDOWS\System32\svchost.exe -k netsvcs
STRUMENTAZIONE GESTIONE WINDOWS: winmgmt
C:\WINDOWS\system32\svchost.exe -k netsvcs
AGGIORNAMENTI AUTOMATICI: wuauserv
C:\WINDOWS\system32\svchost.exe -k netsvcs
ZERO CONFIGURATION RETI SENZA FILI: WZCSVC
C:\WINDOWS\System32\svchost.exe -k netsvcs
SYMANTEC EVENT MANAGER: ccEvtMgr
C:\Programmi\File comuni\Symantec Shared\ccEvtMgr.exe
CLIENT DNS: Dnscache
C:\WINDOWS\System32\svchost.exe -k NetworkService
REGISTRO EVENTI: Eventlog
C:\WINDOWS\system32\services.exe
PLUG AND PLAY: PlugPlay
C:\WINDOWS\system32\services.exe
AMMINISTRAZIONE DI IIS: IISADMIN
C:\WINDOWS\System32\inetsrv\inetinfo.exe
PUBBLICAZIONE FTP: MSFtpsvc
C:\WINDOWS\System32\inetsrv\inetinfo.exe
PROTOCOLLO SMTP (SIMPLE MAIL TRANSFER PROTOCOL): SMTPSVC
C:\WINDOWS\System32\inetsrv\inetinfo.exe
PUBBLICAZIONE SUL WEB: W3SVC
C:\WINDOWS\System32\inetsrv\inetinfo.exe
SERVIZIO NORTON ANTIVIRUS AUTO-PROTECT: navapsvc
"C:\Programmi\Norton AntiVirus\navapsvc.exe"
PIXAR LICENSE SERVER: Pixar License Server
C:\Programmi\Pixar\license-1.0\lmgrd.exe
SERVIZI IPSEC: PolicyAgent
C:\WINDOWS\System32\lsass.exe
ARCHIVIAZIONE PROTETTA: ProtectedStorage
C:\WINDOWS\system32\lsass.exe
GESTIONE ACCOUNT DI PROTEZIONE (SAM): SamSs
C:\WINDOWS\system32\lsass.exe
RPC (REMOTE PROCEDURE CALL): RpcSs
C:\WINDOWS\system32\svchost -k rpcss
SYGATE PERSONAL FIREWALL: SmcService
C:\Programmi\Sygate\SPF\smc.exe
SOUNDMAX AGENT SERVICE: SoundMAX Agent Service (default)
C:\Programmi\Analog Devices\SoundMAX\SMAgent.exe
SPOOLER DI STAMPA: Spooler
C:\WINDOWS\system32\spoolsv.exe
ACQUISIZIONE DI IMMAGINI DI WINDOWS (WIA): stisvc
C:\WINDOWS\System32\svchost.exe -k imgsvc
REMOTE PROCEDURE CALL (RPC) HELPER: O.#´
C:\WINDOWS\netrt.exe /s
|
I got a problem attaching HijackThis log file, so I pasted it into my previous message.
Thanks! _________________ Antonio
|
|
| Back to top |
|
 |
Yellowhammer
Site Moderator Microsoft MVP
 Joined: Jan 30, 2004 Posts: 18022
|
Posted: Wed Jul 21, 2004 10:53 pm Post subject: |
|
|
Download this tool called AboutBuster http://www.downloads.subratam.org/AboutBuster.zip Unzip it to your desktop. Do not run it yet.
**Important** Make sure you can view hidden and system files: Instructions here.
Please do not open Internet Explorer during any portion of this process.
Boot to safe mode: Instructions here.
Click on start, the control panel, then administrative programs, then services. Look for a service called REMOTE PROCEDURE CALL (RPC) HELPER. Double click on the that service and click stop and then set the startup to disabled. Also write down the name and path of the file listed in the Path to executable field. This filename must be deleted below.
Step 2:
Press control-alt-delete to get into the task manager and end the follow processes if they exist:
netrt.exe
d3xq.exe
Step 3:
Run hijackthis and fix these entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\esrnr.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://esrnr.dll/index.html#96676
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://esrnr.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\esrnr.dll/sp.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://esrnr.dll/index.html#96676
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\esrnr.dll/sp.html#96676
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: (no name) - {8EF1A389-7342-F785-A50A-A3C78BA42012} - C:\WINDOWS\system32\apibq32.dll
O4 - HKLM\..\Run: [d3xq.exe] C:\WINDOWS\d3xq.exe
O4 - HKLM\..\RunOnce: [sdkfr32.exe] C:\WINDOWS\sdkfr32.exe
O4 - HKLM\..\RunOnce: [mfcyp.exe] C:\WINDOWS\mfcyp.exe
O4 - HKLM\..\RunOnce: [netrt.exe] C:\WINDOWS\netrt.exe
O4 - HKLM\..\RunOnce: [ntww.exe] C:\WINDOWS\ntww.exe
O4 - HKLM\..\RunOnce: [ntdf32.exe] C:\WINDOWS\system32\ntdf32.exe
O4 - HKLM\..\RunOnce: [ntbw32.exe] C:\WINDOWS\ntbw32.exe
O4 - HKLM\..\RunOnce: [crbn32.exe] C:\WINDOWS\system32\crbn32.exe
O4 - HKLM\..\RunOnce: [sdkpn32.exe] C:\WINDOWS\sdkpn32.exe
O4 - HKLM\..\RunOnce: [d3dl.exe] C:\WINDOWS\d3dl.exe
O4 - HKLM\..\RunOnce: [mfcod.exe] C:\WINDOWS\mfcod.exe
O4 - HKLM\..\RunOnce: [apiel.exe] C:\WINDOWS\system32\apiel.exe
O4 - HKLM\..\RunOnce: [ntxo32.exe] C:\WINDOWS\ntxo32.exe
O4 - HKLM\..\RunOnce: [atlag.exe] C:\WINDOWS\atlag.exe
O4 - HKLM\..\RunOnce: [mszo32.exe] C:\WINDOWS\system32\mszo32.exe
O4 - HKLM\..\RunOnce: [d3qk.exe] C:\WINDOWS\d3qk.exe
O4 - HKLM\..\RunOnce: [javahd32.exe] C:\WINDOWS\system32\javahd32.exe
O4 - HKLM\..\RunOnce: [appds32.exe] C:\WINDOWS\appds32.exe
O4 - HKLM\..\RunOnce: [apipp.exe] C:\WINDOWS\system32\apipp.exe
O4 - HKLM\..\RunOnce: [mfcnn.exe] C:\WINDOWS\mfcnn.exe
O4 - HKLM\..\RunOnce: [mfckl.exe] C:\WINDOWS\system32\mfckl.exe
O4 - HKLM\..\RunOnce: [netlc.exe] C:\WINDOWS\system32\netlc.exe
O4 - HKLM\..\RunOnce: [atlyi32.exe] C:\WINDOWS\system32\atlyi32.exe
O4 - HKLM\..\RunOnce: [addtm32.exe] C:\WINDOWS\system32\addtm32.exe
O4 - HKLM\..\RunOnce: [crad.exe] C:\WINDOWS\crad.exe
O4 - HKLM\..\RunOnce: [javapt.exe] C:\WINDOWS\system32\javapt.exe
O4 - HKLM\..\RunOnce: [javauu32.exe] C:\WINDOWS\javauu32.exe
O4 - HKLM\..\RunOnce: [d3yp.exe] C:\WINDOWS\system32\d3yp.exe
O4 - HKLM\..\RunOnce: [crwo32.exe] C:\WINDOWS\crwo32.exe
O4 - HKLM\..\RunOnce: [ieim32.exe] C:\WINDOWS\system32\ieim32.exe
O4 - HKLM\..\RunOnce: [sysyu.exe] C:\WINDOWS\sysyu.exe
O4 - HKLM\..\RunOnce: [mfcrr.exe] C:\WINDOWS\system32\mfcrr.exe
O4 - HKLM\..\RunOnce: [atlfg.exe] C:\WINDOWS\system32\atlfg.exe
O4 - HKLM\..\RunOnce: [winvr32.exe] C:\WINDOWS\winvr32.exe
O4 - HKLM\..\RunOnce: [iebp.exe] C:\WINDOWS\system32\iebp.exe
O4 - HKLM\..\RunOnce: [ipyn.exe] C:\WINDOWS\ipyn.exe
O4 - HKLM\..\RunOnce: [mspm.exe] C:\WINDOWS\mspm.exe
O4 - HKLM\..\RunOnce: [javaee.exe] C:\WINDOWS\system32\javaee.exe
O4 - HKLM\..\RunOnce: [addfm32.exe] C:\WINDOWS\addfm32.exe
O4 - HKLM\..\RunOnce: [addrs.exe] C:\WINDOWS\addrs.exe
O4 - HKLM\..\RunOnce: [crfy.exe] C:\WINDOWS\system32\crfy.exe
O4 - HKLM\..\RunOnce: [crrd.exe] C:\WINDOWS\crrd.exe
O4 - HKLM\..\RunOnce: [apptr32.exe] C:\WINDOWS\system32\apptr32.exe
O4 - HKLM\..\RunOnce: [d3wk.exe] C:\WINDOWS\d3wk.exe
O4 - HKLM\..\RunOnce: [apilk32.exe] C:\WINDOWS\apilk32.exe
O4 - HKLM\..\RunOnce: [iedm.exe] C:\WINDOWS\system32\iedm.exe
O4 - HKLM\..\RunOnce: [javagm.exe] C:\WINDOWS\system32\javagm.exe
O4 - HKLM\..\RunOnce: [ntjw32.exe] C:\WINDOWS\ntjw32.exe
O4 - HKLM\..\RunOnce: [netdo32.exe] C:\WINDOWS\netdo32.exe
O4 - HKLM\..\RunOnce: [sysuc32.exe] C:\WINDOWS\system32\sysuc32.exe
O4 - HKLM\..\RunOnce: [sdknd32.exe] C:\WINDOWS\system32\sdknd32.exe
O4 - HKLM\..\RunOnce: [addko.exe] C:\WINDOWS\addko.exe
O4 - HKLM\..\RunOnce: [mfcdh32.exe] C:\WINDOWS\system32\mfcdh32.exe
O4 - HKLM\..\RunOnce: [sdkij32.exe] C:\WINDOWS\system32\sdkij32.exe
O4 - HKLM\..\RunOnce: [msen.exe] C:\WINDOWS\system32\msen.exe
O4 - HKLM\..\RunOnce: [msug.exe] C:\WINDOWS\msug.exe
O4 - HKLM\..\RunOnce: [crkf32.exe] C:\WINDOWS\crkf32.exe
O4 - HKLM\..\RunOnce: [winqj.exe] C:\WINDOWS\system32\winqj.exe
O4 - HKLM\..\RunOnce: [sysgh32.exe] C:\WINDOWS\sysgh32.exe
O4 - HKLM\..\RunOnce: [d3ud32.exe] C:\WINDOWS\d3ud32.exe
O4 - HKLM\..\RunOnce: [netnm.exe] C:\WINDOWS\system32\netnm.exe
O4 - HKLM\..\RunOnce: [apihs32.exe] C:\WINDOWS\system32\apihs32.exe
O4 - HKLM\..\RunOnce: [addfp.exe] C:\WINDOWS\addfp.exe
O4 - HKLM\..\RunOnce: [sdkqf32.exe] C:\WINDOWS\sdkqf32.exe
O4 - HKLM\..\RunOnce: [crpn32.exe] C:\WINDOWS\system32\crpn32.exe
O4 - HKLM\..\RunOnce: [netae.exe] C:\WINDOWS\netae.exe
O4 - HKLM\..\RunOnce: [iewb.exe] C:\WINDOWS\system32\iewb.exe
O4 - HKLM\..\RunOnce: [addkz32.exe] C:\WINDOWS\system32\addkz32.exe
O4 - HKLM\..\RunOnce: [ipdv.exe] C:\WINDOWS\ipdv.exe
O4 - HKLM\..\RunOnce: [ntqs32.exe] C:\WINDOWS\system32\ntqs32.exe
O4 - HKLM\..\RunOnce: [winoo.exe] C:\WINDOWS\system32\winoo.exe
O4 - HKLM\..\RunOnce: [ipwi.exe] C:\WINDOWS\system32\ipwi.exe
O4 - HKLM\..\RunOnce: [atlzb.exe] C:\WINDOWS\atlzb.exe
O4 - HKLM\..\RunOnce: [sysss.exe] C:\WINDOWS\sysss.exe
O4 - HKLM\..\RunOnce: [appfh32.exe] C:\WINDOWS\appfh32.exe
O4 - HKLM\..\RunOnce: [sysyh.exe] C:\WINDOWS\sysyh.exe
O4 - HKLM\..\RunOnce: [msge.exe] C:\WINDOWS\system32\msge.exe
Step 4:
Delete the following files:
C:\WINDOWS\system32\esrnr.dll
C:\WINDOWS\system32\apibq32.dll
C:\WINDOWS\netrt.exe
C:\WINDOWS\d3xq.exe
C:\WINDOWS\sdkfr32.exe
C:\WINDOWS\mfcyp.exe
C:\WINDOWS\ntww.exe
C:\WINDOWS\system32\ntdf32.exe
C:\WINDOWS\ntbw32.exe
C:\WINDOWS\system32\crbn32.exe
C:\WINDOWS\sdkpn32.exe
C:\WINDOWS\d3dl.exe
C:\WINDOWS\mfcod.exe
C:\WINDOWS\system32\apiel.exe
C:\WINDOWS\ntxo32.exe
C:\WINDOWS\atlag.exe
C:\WINDOWS\system32\mszo32.exe
C:\WINDOWS\d3qk.exe
C:\WINDOWS\system32\javahd32.exe
C:\WINDOWS\appds32.exe
C:\WINDOWS\system32\apipp.exe
C:\WINDOWS\mfcnn.exe
C:\WINDOWS\system32\mfckl.exe
C:\WINDOWS\system32\netlc.exe
C:\WINDOWS\system32\atlyi32.exe
C:\WINDOWS\system32\addtm32.exe
C:\WINDOWS\crad.exe
C:\WINDOWS\system32\javapt.exe
C:\WINDOWS\javauu32.exe
C:\WINDOWS\system32\d3yp.exe
C:\WINDOWS\crwo32.exe
C:\WINDOWS\system32\ieim32.exe
C:\WINDOWS\sysyu.exe
C:\WINDOWS\system32\mfcrr.exe
C:\WINDOWS\system32\atlfg.exe
C:\WINDOWS\winvr32.exe
C:\WINDOWS\system32\iebp.exe
C:\WINDOWS\ipyn.exe
C:\WINDOWS\mspm.exe
C:\WINDOWS\system32\javaee.exe
C:\WINDOWS\addfm32.exe
C:\WINDOWS\addrs.exe
C:\WINDOWS\system32\crfy.exe
C:\WINDOWS\crrd.exe
C:\WINDOWS\system32\apptr32.exe
C:\WINDOWS\d3wk.exe
C:\WINDOWS\apilk32.exe
C:\WINDOWS\system32\iedm.exe
C:\WINDOWS\system32\javagm.exe
C:\WINDOWS\ntjw32.exe
C:\WINDOWS\netdo32.exe
C:\WINDOWS\system32\sysuc32.exe
C:\WINDOWS\system32\sdknd32.exe
C:\WINDOWS\addko.exe
C:\WINDOWS\system32\mfcdh32.exe
C:\WINDOWS\system32\sdkij32.exe
C:\WINDOWS\system32\msen.exe
C:\WINDOWS\msug.exe
C:\WINDOWS\crkf32.exe
C:\WINDOWS\system32\winqj.exe
C:\WINDOWS\sysgh32.exe
C:\WINDOWS\d3ud32.exe
C:\WINDOWS\system32\netnm.exe
C:\WINDOWS\system32\apihs32.exe
C:\WINDOWS\addfp.exe
C:\WINDOWS\sdkqf32.exe
C:\WINDOWS\system32\crpn32.exe
C:\WINDOWS\netae.exe
C:\WINDOWS\system32\iewb.exe
C:\WINDOWS\system32\addkz32.exe
C:\WINDOWS\ipdv.exe
C:\WINDOWS\system32\ntqs32.exe
C:\WINDOWS\system32\winoo.exe
C:\WINDOWS\system32\ipwi.exe
C:\WINDOWS\atlzb.exe
C:\WINDOWS\sysss.exe
C:\WINDOWS\appfh32.exe
C:\WINDOWS\sysyh.exe
C:\WINDOWS\system32\msge.exe
Also delete any files that have the same name as these files but end with a dll. You should see them right next to each other.
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
Step 5:
Go to Start->Run and type Regedit then click Ok. Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services
and highlight Services in the left pane. In the right pane, look for any of these entries:
__NS_Service
__NS_Service_2
__NS_Service_3
If any are listed, right-click that entry in the right pane and choose Delete.
Again in Regedit, navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root and highlight Root in the Left Pane. In the right pane, look for these entries (the number at the end should correspond to the first one you deleted above):
LEGACY___NS_Service
LEGACY___NS_Service_2
LEGACY___NS_Service_3
If you find it, right-click it in the right-pane and choose delete.
If you have trouble deleting a key. Then click once on the key name (LEGACY__NS_SERVICE_ or some other name that starts with LEGACY__NS_SERVICE) to highlight it and click on the Permission menu option under Security or Edit. Then Uncheck "Allow inheritible permissions" and press copy. Then click on everyone and put a checkmark in "full control". Then press apply and ok and attempt to delete the key again.
Step 6:
Then browse to the C:\documents and settings\Maximum Mortgage (Repeat for all user names)\local settings\temp folder and delete all files and folders in it.
Then browse to the C:\Windows\Temp folder and delete all files in it.
Then in internet explore click tools>internet Options>General. Click on Delete Files make sure you get all offline content as well.
Empty the Recycle bin.
Reboot to Normal Mode.
Step 7:
Double click AboutBuster.exe that you downloaded earlier. Click OK, click Start, then click OK. This will scan your computer for the bad files and delete them. Save the report(copy and paste into notepad or word pad and save as a .txt file) and post a copy back here when you are done with all the steps.
Step 8:
Restore files deleted by this malware.
Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program.
If you have Spybot S&D installed you will also need to replace one file.
Go here and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy)
If you are having any problems opening the control panel go here, and download control.exe per the instructions at the site.
Additionally, Please check your ActiveX security settings. They may have been changed by this CWS variant to allow ALL ActiveX!! If they have been changed, reset your active x security settings in IE as recommended here.
Look in your system32 folder for shell.dll
If it is not there, Go into System32\dllcache
Find shell.dll
Right click on shell.dll and choose copy from the menu.
Go back into the System32 Folder and right click on an empty space in the folder. Choose paste fom the menu. this will replace the missing shell.dll
for you.
Step 9:
Do an online scan using Trend Micros Housecall. It is available here.
Step 10:
Then Disable system restore: Instructions here.
Reboot
Enable system restore.
Scan and post another hijackthis log. _________________ Yellowhammer
MS-MVP Security 2005/2006
How to prevent Reinfection
|
|
| Back to top |
|
 |
moparguy
Trooper

 Joined: Aug 19, 2004 Posts: 11 Location: USA
|
Posted: Thu Aug 19, 2004 11:09 pm Post subject: crad.exe |
|
|
Hi,
The above description is identical to a problem I have and I have zero'd in on a process running as "crad.exe" as the culprit. Do you have a fix file for it or do I need to follow the procedure listed above??
Thanks
MoparGuy
|
|
| Back to top |
|
 |
Yellowhammer
Site Moderator Microsoft MVP
 Joined: Jan 30, 2004 Posts: 18022
|
Posted: Thu Aug 19, 2004 11:11 pm Post subject: |
|
|
moparguy,
Post a hijackthis log in a new topic and I will be glad to look at it. Each fix is different. After you post, send me a pm and I will look at it. _________________ Yellowhammer
MS-MVP Security 2005/2006
How to prevent Reinfection
|
|
| Back to top |
|
 |
|
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|