PDA

View Full Version : Curious


mps69_1999
01-06-2004, 06:28 PM
Hi
During my last last virus scan I found a Trojan, how it got there and when it got there is beyond me, but is still got past my firewall and virus checker.
This is what is found.
Source:C:\WINDOWS\SYSTEM32\iexplore.exe
Description: The file C:\WINDOWS\SYSTEM32\iexplore.exe is infected with the Backdoor.Trojan virus.
All was removed ok, however my PC just isn't running the same. The old gut feeling thing. I did notice the date had changed to the year 2165, but nothing i could put my finger on. I've ran hijackthis, if someone could take a look at it and let me know if there is anything out of the ordinary it would be great.
Logfile of HijackThis v1.94.0
Scan saved at 22:16:32, on 06/01/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.imdb.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\SYSTEM\blank.htm
O1 - Hosts: 216.40.230.4 desktop.kazaa.com
O1 - Hosts: 216.40.230.4 alpha.kazaa.com
O1 - Hosts: 216.40.230.4 shop.kazaa.com
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - d:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Program Files\NavShExt.dll
O2 - BHO: (no name) - {FFFFFEF0-5B30-21D4-945D-000000000000} - D:\PROGRA~1\STARDO~1\SDIEInt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Program Files\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "D:\program files\qttask.exe" -atboottime
O8 - Extra context menu item: Download with Star Downloader - D:\PROGRA~1\STARDO~1\sdie.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/c381/chat.cab
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} (Microsoft Office Template and Media Control) - http://office.microsoft.com/templates/ieawsdc.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/viewers/ipixx.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/swdir.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37749.4390856481
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - http://help.blueyonder.co.uk/instantsupport/tool/files/MotivePreQual.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://http.gamezone.tukati.com/tukati/1.7.20.20/tukati.cab

The only one I don't really understand is the last one what it is and how I might have got it.
Many Thanks people
mps

Budfred
01-07-2004, 12:01 AM
Well, I can see how you might have gotten infested in the first place since it appears you may have run Kazaa....

You can fix these with HJT, if any of the first one's are legit, they will get restablished when you get back online. However, I don't think they are good and the O1 items are hijacks...

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page=http://www.imdb.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\System32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page=C:\WINDOWS\SYSTEM\blank.htm
O1 - Hosts: 216.40.230.4 desktop.kazaa.com
O1 - Hosts: 216.40.230.4 alpha.kazaa.com
O1 - Hosts: 216.40.230.4 shop.kazaa.com

Unless you know what this is, I would fix it too:

O16 - DPF: {FE5D6722-826F-11D5-A24E-0060B0F1A5AE} (Tukati Launcher) - http://http.gamezone.tukati.com/tuk...0.20/tukati.cab

You also need to post the Running Processes part of the log since the main problem may be there. If you are running HJT from a temp folder, you also need to extract it to a folder like C:\Documents or one you create so you can restore changes if needed...

Once you run HJT, reboot, run it again, open your browser and post a new log here....

shanmuga
01-07-2004, 01:16 AM
As you are once affected by a trojan, I would suggest that you follow this procedure, to be sure.

1.Download, install and update either TDS-3 from http://www.diamondcs.com.au/index.php?page=home or TrojanHunter from http://www.misec.net/products. Record exactly the names of any problems it turns up. Then quarantine and cure the malware.

2. Update and run the AV product you currently have installed on your computer. If any malware is turned up,note down the name, quarantine and cure the malware.

3. Run one or two of the web based AV scanners. Once again note down the names of any malware it turns up. Then quarantine and cure the malware.

http://security.symantec.com
http://housecall.trendmicro.com
http://www.ravantivirus.com/scan
http://www.pandasoftware.com/activescan

4. Download, install, update and run Ad-aware.Notedown the names of any problems it turns up. Then quarantine and cure the malware.

http://www.lavasoftusa.com

5. Download, install, update, restart, and run Spybot S&D. Notedown the names of any problems it turns up. Then quarantine and cure the malware.

http://security.kolla.de

If problems remain:

6. Download and run HiJackThis.Also, make sure that you actually extract HijackThis to its own folder. DO NOT run it from within a zip manager (Winzip), as no backups will be saved.

This procedure will give you a chance to remove any malware with the automated detection and removal provided by the above programs. HiJackThis should only be used as a last resort because it is a sort of manual removal method, IMHO.

You have ran the scan with a dated version of HijackThis, download the latest version from http://mjc1.com/mirror/hjt/ . Please note to post the full log here.