Register   FAQ   Login  

Malicious file removal problem





AddThis Social Bookmark Button AddThis Feed Button

       2-spyware forum index -> Removal of spyware, adware and other parasites
Author Message
Velcropants



Joined: 05 Aug 2008
Posts: 3

Post Post subject: Malicious file removal problem Reply with quote

Hey guys, been cleaning a computer, there was a crap load of viruses on it, and its recently just stopped connecting to the internet. Its using XP service pack 2. Im having one problem in particular. Theres a trojan or something of the like blocking the internet connection, it connects to my lan absolutely fine, but it wont let any progrom including browsers connect using it. It may have also taken over some admin privilages although this im not sure.

I did a full scan using Ad aware and AVG free (latest versions) and they both removed a hefty ammount of viruses from the system, (about 600) but both cant seem to remove 1 or two that are floating about. On avg everytime i try it says access is denied.

On AVG it keeps saying access is denied for healing/quarantine. It says its in C:\WINDOWS\system32\drivers\core


heres the details froma ad-aware:

Win 32. Trojan Agent malware -- TAI 10

Registry entry Root HKLM path: system\controlset002\services\core
Registry entry Root HKLM path: system\currentcontrolset\services\core

every time i try to remove it from ad-awares scanning list it simply unchecks it and refuses to delete it.

Finally i used Hijack this 2.002 but im not too sure what to delete as im still new to reg edits etc.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:05:31, on 05/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\Documents and Settings\alan\Desktop\hijackthis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Internet Explorer Plugin - {42E8CF0E-948C-4FBE-B0CB-A39AD4304C28} - C:\WINDOWS\system32\PluginE.dll (file missing)
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdate.exe] C:\Program Files\Windows\WinUpdate.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\webhancer\programs\webhdll.dll' missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {38D63471-E630-4492-A986-B8C48B79F2F8} (CVideoEgg_ActiveXCtl Object) - http://update.videoegg.com/wintel/VideoEggPublisher.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{902269FE-2CD6-438E-BF9A-18EDF91FB853}: NameServer = 159.134.237.6,159.134.248.17
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: Ext - C:\WINDOWS\system32\r8p80i7ue8.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: CreateProcess Service (CreateProcess) - Unknown owner - C:\WINDOWS\system\svchost.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

--
End of file - 6022 bytes


the last thing i want to do is delete the wrong thing and destroy all the personal files on the computer. So please, im in desperate need, and very very frustrated, can you guys help me? I greatly appreciate it.
Tue Aug 05, 2008 9:04 am
Back to top
Velcropants View user's profile Send private message
 
Bobby



Joined: 03 May 2006
Posts: 290

Post Post subject: Reply with quote

hello there,

well you got several options there.

if you want to fix everything as soon as possible and make it in the least painful way, you can copy all important files, documents, etc to dvds or external drives, then format drives on your computer and re-install windows. this way all of malwares will be gone for sure. however, you can also fight the infection, then the format won't be necessary.

i recommend running one more or maybe two more antspyware scans. different antispywares detect different things, so there's high possibility that new antispyware will remove things left by Ad aware and AVG. you can download free antispyware tools right here : http://www.2-spyware.com/compare2.php .

if this plan won;t work either, please post a new hijackthis log at hijackthis logs analysis forum : http://www.2-spyware.com/forum/forum8
_________________
I reccomend Spyware Doctor and Malwarebytes’ Anti-malware as ultimate protection.
Wed Aug 06, 2008 5:14 am
Back to top
Bobby View user's profile Send private message
 
Velcropants



Joined: 05 Aug 2008
Posts: 3

Post Post subject: Reply with quote

Thanks bobby,

I've tried installing spybot seek and destroy, but its blocked or access is again denied. Windows defender is on the computer and didnt pick up a thing Razz

Thanks so much for the heads up. I'd prefer not to dwipe/do a clean install as this is a friends computer, unless i absolutely had to. Any recommendations on how to clean it up manually? I'll repost the log in the Hijack this forum. cheers again!
Wed Aug 06, 2008 4:30 pm
Back to top
Velcropants View user's profile Send private message
 
stallion50



Joined: 30 Jan 2009
Posts: 2
Location: Columbia SC

Post Post subject: Reply with quote

I posted a fix that will help you if you still need it Jan 30
Sat Jan 31, 2009 12:13 am
Back to top
stallion50 View user's profile Send private message Send e-mail
 
       2-spyware forum index -> Removal of spyware, adware and other parasites All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




Recommended software:
Spyware Doctor
(91/100)
Spyware Doctor is a very powerful, but yet highly user-friendly spyware remover, made by PC Tools, reputable computer security experts. This product provides effective and easy-to-manage...
Malwarebytes Anti Malware
(89/100)
There are loads of malware removers on the net today and most of them are lightweight applications, which usually means they’re fast and don’t have many features. One such...
Spy Sweeper
(85/100)
Spy Sweeper is one of the most powerful and effective spyware removers available today. This Webroot Software's product uses unique, patent-pending parasite detection and removal...
Windows Defender
(80/100)
Windows Defender is a free anti-spyware program made by the leading software company to add native spyware protection to its most popular product - the Microsoft Windows operating...
SUPERAntiSpyware
(75/100)
SUPERAntiSpyware is a powerful, highly effective spyware remover introducing advanced parasite detection and removal features along with reliable real-time protection. The program is not...
Encyclopedia of parasites: