Author Topic: PLease HELP!!!  (Read 8723 times)

0 Members and 2 Guests are viewing this topic.

Offline MA

  • Newbie
  • *
  • Posts: 32
Re: PLease HELP!!!
« Reply #45 on: July 20, 2009, 09:04:55 PM »
What's the next step?

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: PLease HELP!!!
« Reply #46 on: July 20, 2009, 10:06:49 PM »
Please do the following:

1)  Adobe Reader has been updated due to vulnerabilities.  I strongly suggest you uninstall the current version and upgrade to the latest from http://www.adobe.com/products/reader/ or switch to an alternate PDF reader.  Adobe Acrobat has also been updated.  You can compare the versions here:  http://www.adobe.com/products/acrobat/matrix.html Note, that there are a number of open source readers available from http://pdfreaders.org/ , many of which provide the same or similar functions as Adobe Acrobat. 

2)  Custom CFScript

Note: The following instructions were created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


  • Please open Notepad (Click Start -> Run -> type notepad in the Open field -> OK).  Copy/Paste all of the text present inside the code box below:
Code: [Select]
File::
c:\windows\system32\m?hta.exe

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Vyml"=-
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -
  • Save this as CFScript.txt and place it on your desktop.
  • Close any open browsers.
  • Close/disable all antivirus and anti-malware programs so they do not interfere with the running of ComboFix.




  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it will produce a log for you. Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline MA

  • Newbie
  • *
  • Posts: 32
Re: PLease HELP!!!
« Reply #47 on: July 21, 2009, 12:07:35 PM »
ComboFix 09-07-20.04 - Administrator 07/21/2009  9:54.2.1 - FAT32x86
Microsoft Windows XP Professional  5.1.2600.2.1255.972.1033.18.254.112 [GMT 2:00]
Running from: c:\documents and settings\Administrator.HOME-B1BE68320F\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator.HOME-B1BE68320F\Desktop\CFScript.txt
AV: ESET Smart Security 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: ESET Personal firewall *enabled* {E5E70D32-0101-4340-86A3-A7B0F1C8FFE0}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

(((((((((((((((((((((((((   Files Created from 2009-06-21 to 2009-07-21  )))))))))))))))))))))))))))))))
.

2009-07-19 12:45 . 2009-07-19 12:45   --------   d-----w-   c:\documents and settings\Administrator.HOME-B1BE68320F\Application Data\ESET
2009-07-19 12:43 . 2009-07-19 12:43   --------   d-----w-   c:\documents and settings\All Users\Application Data\ESET
2009-07-19 11:17 . 2009-07-19 11:17   --------   d-----w-   c:\program files\trend micro
2009-07-19 11:17 . 2009-07-19 11:17   --------   d-----w-   C:\rsit
2009-07-18 21:48 . 2009-07-18 21:48   --------   d-----w-   c:\program files\ESET
2009-07-18 20:02 . 2009-07-18 20:02   --------   d-----w-   c:\documents and settings\Administrator.HOME-B1BE68320F\Application Data\Malwarebytes
2009-07-18 20:02 . 2009-07-13 11:36   38160   ----a-w-   c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-18 20:02 . 2009-07-18 20:02   --------   d-----w-   c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-18 20:02 . 2009-07-13 11:36   19096   ----a-w-   c:\windows\system32\drivers\mbam.sys

.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-28 20:41 . 2007-10-11 21:58   36   ---ha-w-   c:\windows\system32\f9t.dat
2009-05-28 08:00 . 2009-05-28 08:00   56   ---ha-w-   c:\windows\system32\ezsidmv.dat
2009-05-28 08:00 . 2009-05-28 08:00   --------   d-----w-   c:\documents and settings\Administrator.HOME-B1BE68320F\Application Data\skypePM
2009-05-28 08:00 . 2009-05-28 08:00   --------   d-----w-   c:\program files\Common Files\Skype
2009-05-14 13:49 . 2009-05-14 13:49   55768   ----a-w-   c:\windows\system32\drivers\epfwtdi.sys
2009-05-14 13:49 . 2009-05-14 13:49   33096   ----a-w-   c:\windows\system32\drivers\epfwndis.sys
2009-05-14 13:49 . 2009-05-14 13:49   133000   ----a-w-   c:\windows\system32\drivers\epfw.sys
2009-05-14 13:47 . 2009-05-14 13:47   107256   ----a-w-   c:\windows\system32\drivers\ehdrv.sys
2009-05-14 13:41 . 2009-05-14 13:41   114472   ----a-w-   c:\windows\system32\drivers\eamon.sys
2005-10-10 20:53 . 2005-10-10 20:53   1338   ----a-w-   c:\program files\0007EDF2.key
.

(((((((((((((((((((((((((((((   SnapShot@2009-07-20_20.00.52   )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-21 07:33 . 2009-07-21 07:33   16384              c:\windows\Temp\Perflib_Perfdata_66c.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-11 39408]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-05-25 25477928]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2002-10-16 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2002-10-16 114688]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-01-13 69632]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-15 196608]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-09-11 229952]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-12-11 286720]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2009-05-14 2029640]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2003-04-25 54784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Administrator.HOME-B1BE68320F\Start Menu\Programs\Startup\
HotSync Manager.lnk - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-1-19 113664]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute   REG_MULTI_SZ      autocheck autochk *\0SsiEfr.exe\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\fxsclnt.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 bckd;bckd;c:\windows\system32\drivers\bckd.sys [14/01/2009 01:39 72992]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [14/05/2009 15:47 107256]
R2 bckwfs;Blue Coat K9 Web Protection;c:\program files\Blue Coat K9 Web Protection\k9filter.exe [28/03/2006 17:29 1078560]
R2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [14/05/2009 15:47 731840]
R2 SpPortEx;Samsung Port Exclusion;c:\windows\system32\drivers\SpPortEx.sys [07/12/2005 17:50 7168]
S3 M1000Srv;M5603C USB2.0 Camera Driver;c:\windows\system32\drivers\M1000KNT.sys [19/11/2006 14:18 449483]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.jerusalemcompass.com/catalog/index.php
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &יצא ל- Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Add to AMV Convert Tool... - c:\program files\MP3 Player Utilities 3.79\AMVConverter\grab.html
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 3.79\MediaManager\grab.html
TCP: {4ADFFFD8-EE70-4A87-8A08-278D42E61A9F} = 208.67.222.222,208.67.220.220
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-21 09:59
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ... 

scanning hidden autostart entries ...

scanning hidden files ... 

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-789336058-1659004503-682003330-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*, D*S*_*S*t*o*r*e*\OpenWithList]
@Class="Shell"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(2260)
c:\program files\ScanSoft\OmniPageSE\ophook32.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
I did as you requested. I also deleted my adobe reader, and acrobot before the scan.

c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-07-21 10:01
ComboFix-quarantined-files.txt  2009-07-21 08:01
ComboFix2.txt  2009-07-20 20:05

Pre-Run: 8,971,649,024 bytes free
Post-Run: 8,948,088,832 bytes free

126

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: PLease HELP!!!
« Reply #48 on: July 21, 2009, 02:08:08 PM »
Hi, MA.

Please do the following to implement cleanup procedures and also to reset System Restore points:

1.  Click Start > Run and Copy/Paste the following bolded text into the Run box and click OK:  ComboFix /u



Note: In the event you wish to contribute to the ongoing development of ComboFix, the developer is accepting donations via PayPal.


2.  It is strongly recommended to have the Windows Recovery Console installed on your machine. The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. It is a simple procedure that will only take a few moments of your time.

Go to Microsoft's website => http://support.microsoft.com/kb/310994

Select the download that's appropriate for your Operating System



Download the file & save it as it's originally named.

3.  Having a firewall, anti-virus and anti-malware software are not enough.  You also need to stay current with security updates.  If you don't have your computer set to automatically install the Microsoft Security Updates, please check for updates now.  For additional information, see my blog post Understanding Microsoft Updates

4.  To further check if your system is missing security updates or has insecure applications installed, visit http://secunia.com/software_inspector/ .  The Secunia Software Inspector runs through your browser with no installation or download required and does the following:
  • Detects insecure versions of applications installed
  • Verifies that all Microsoft patches are applied
  • Assists you in updating your system and applications

5.  Install and update SpywareBlaster to prevent the installation of spyware and other potentially unwanted software: http://www.javacoolsoftware.com/spywareblaster.html

6.  My favorite security software is WinPatrol which includes the features described at http://www.winpatrol.com/features.html

Please let me know if you have any questions.
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline MA

  • Newbie
  • *
  • Posts: 32
Re: PLease HELP!!!
« Reply #49 on: July 21, 2009, 03:19:39 PM »
First  I wish to thank you, and everyone for all of the help :)

Quote
It is strongly recommended to have the Windows Recovery Console installed on your machine.

When I purchased my computer, several years ago, I think that they installed a Non registered version of the XP. So, when my computer was doing the automatic updates, one day I got a window that, "you are running an invalid version of windows etc.....and then they basically shut me down, telling me to go and install a "valid" version, (so that I would be protected properly etc.)
  I went to the computer store. They took care of that problem, and then turned off the "auto updates" so that it wouldn't happen again.
  So, what would you do in this case?

Offline MA

  • Newbie
  • *
  • Posts: 32
Re: PLease HELP!!!
« Reply #50 on: July 21, 2009, 03:31:42 PM »
.....Going back to the beginning of my thread with my laptop, you had basically declared it a lost case:
Hi, MA.

I am sorry to be the bearer of bad news.  One of the reasons you cannot run an .exe file is that Sality essentially infects every .exe file.  The only cure will be a format and install from scratch. 

Quote
You also provided information from the scan identifying a backdoor trojan.  After seeing the Malwarebytes' log, it appears there is more than one backdoor trojan on the computer.  Backdoors cause severe damage to windows' internals, and allow an attacker complete control over the infected system. Because this state allows the attacker to download new malware on demand, log keystrokes, execute programs, and/or view the system's screen, it is recommended to reformat and reinstall the operating system on this machine. Several experts in the security community believe that once a system is infected with one of these types of backdoors, the system itself can never be trusted again.

1) I imagine the answer is "NO", but would "system restore" take care of this problem?

2) Also, on one of the articles you sent me about my predicament,i.e when to reformat or not,and how dangerous is the threat etc: I think they mentioned that it "may not be so bad", if I was using this sytem via a router, (which is what I did exclusively). What do you say?

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: PLease HELP!!!
« Reply #51 on: July 21, 2009, 06:09:34 PM »
First  I wish to thank you, and everyone for all of the help :)

You're welcome.

When I purchased my computer, several years ago, I think that they installed a Non registered version of the XP. So, when my computer was doing the automatic updates, one day I got a window that, "you are running an invalid version of windows etc.....and then they basically shut me down, telling me to go and install a "valid" version, (so that I would be protected properly etc.)
  I went to the computer store. They took care of that problem, and then turned off the "auto updates" so that it wouldn't happen again.
  So, what would you do in this case?

If the computer store "took care of the problem," in which case you should have a Certificate of Authenticity, then your computer would have validated so why would they turn off automatic updates?  With autoupdate, ALL security updates will download and install automatically regardless of WGA status. 

Quote
In Windows XP, there are only two levels of updates: High-priority and Optional.

When you turn on Automatic Updates in Windows XP, Windows will routinely check for High-priority updates that can help protect your PC from the latest viruses and other security threats. These updates can include security updates, critical updates, and service packs.
http://www.microsoft.com/windows/downloads/windowsupdate/updatelevels.mspx#EDD

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: PLease HELP!!!
« Reply #52 on: July 21, 2009, 06:23:17 PM »
.....Going back to the beginning of my thread with my laptop, you had basically declared it a lost case:
Hi, MA.

I am sorry to be the bearer of bad news.  One of the reasons you cannot run an .exe file is that Sality essentially infects every .exe file.  The only cure will be a format and install from scratch.  

Quote
You also provided information from the scan identifying a backdoor trojan.  After seeing the Malwarebytes' log, it appears there is more than one backdoor trojan on the computer.  Backdoors cause severe damage to windows' internals, and allow an attacker complete control over the infected system. Because this state allows the attacker to download new malware on demand, log keystrokes, execute programs, and/or view the system's screen, it is recommended to reformat and reinstall the operating system on this machine. Several experts in the security community believe that once a system is infected with one of these types of backdoors, the system itself can never be trusted again.

1) I imagine the answer is "NO", but would "system restore" take care of this problem?

2) Also, on one of the articles you sent me about my predicament,i.e when to reformat or not,and how dangerous is the threat etc: I think they mentioned that it "may not be so bad", if I was using this sytem via a router, (which is what I did exclusively). What do you say?


Do you know when the computer was infected?  How far back do the restore points go?  In other words, when you posted on July 16, you told us:

Quote
Usually when I start up my computer, I have about 5-10 minutes to do something before the computer shuts down, only to restart again. This can go on and on .  If I am quick, I can use some of my email program...until that shuts down. Even skype, but no programs that have to do with computer security.

With the passing of time, as new check points are created, old restore points are removed to make room for the new points.  Thus, the timeframe depends upon the amount of space allotted for System Restore.

The "may not be so bad" was not in reference to infections such as Sality.   
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Offline MA

  • Newbie
  • *
  • Posts: 32
Re: PLease HELP!!!
« Reply #53 on: July 21, 2009, 06:41:41 PM »
Quote
Do you know when the computer was infected?  How far back do the restore points go?  In other words, when you posted on July 16, you told us:

If you think that this YES would be a solution, then I would have to look into it asap, to try to determine when. But, if it is like this computer, then I would have at least 2 months to go back. HOWEVER, something did happen to this option because when I click on system restore, it says, "System restore has been turned off by group policy. To turn on System Restore, contact your domain administrator."

If you think that system restore is worth looking into, EVEN taking into account how serious it was affected, then can you help me get the system restore back into my hands?

And concerning Window updates:
Quote
If the computer store "took care of the problem," in which case you should have a Certificate of Authenticity, then your computer would have validated so why would they turn off automatic updates?
   
What I meant was, since I do NOT have a certificate of authenticity, they "took care of the problem", i.e. getting my computer to work again,and turning off the automatic updates. So, is there is another solution instead of the windows restore console ??

Online Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11541
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: PLease HELP!!!
« Reply #54 on: July 21, 2009, 07:28:54 PM »
The infection turned off system restore.  You have no restore points to go use.  You need to reinstall the software from the original CD.

Quote
When I purchased my computer, several years ago, I think that they installed a Non registered version of the XP.
They may have used an OEM license which should have been provided to you.  However, if that store is still in business, I would dig out the paperwork and march back there and insist they reinstall the system and provide you with a valid COA.  Otherwise, submit a counterfeit report at www.microsoft.com/howtotell/report or at piracy@microsoft.com . In your report, explain where you purchased the computer. 

,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.