• Navigation
Results 1 to 13 of 13
  1. #1
    blax n gunz
    Join Date
    May 2005
    Posts
    11,141
    BG Level
    9

    Cleaned up multiple trojans, still can't use internet

    Sooo, dailymotion's rotating flash banners got me infected with some fun stuff. AVG found:

    SHeur2.AWBO
    Generic14.UWP
    Win32/Cryptor

    And after running a full scan with AVG and quick scans with Malwarebytes/SuperAntiSpyware + several restarts, web searches and runs through gpedit.msc I think I have my computer back. The problem is I can't connect to the internet. ipconfig finds my adapter. My laptop can connect with the wireless radio in my combo router, so my ISP/router are both fine. Internet Options has 'automatically detect settings' checked off. I've flushed my DNS cache. Still zilch. Hijack this has an interesting line in it:

    "Broken Internet access because of LSP provider 'c:\windows\system32\winhelper.dll' missing"

    That looks like one of the dlls my antivirus removed to clean up the trojans. Did it clobber a legit windows dll? Am I going to have to dig up and find my xp install CD to restore this or is there something I'm missing in the Hijack this log, pasted below:

    Spoiler: show

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:19:04 PM, on 8/12/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\System32\svchost.exe
    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\PROGRA~1\AVG\AVG8\avgtray.exe
    C:\Program Files\lg_fwupdate\fwupdate.exe
    C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\HPLamp.exe
    C:\Program Files\Cyberlink\Shared Files\brs.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC 2.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\AVG\AVG8\avgui.exe
    C:\Program Files\AVG\AVG8\avgcsrvx.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    F2 - REG:system.ini: Shell=Explorer.exe logon.exe
    O2 - BHO: (no name) - {39FF76AC-2577-46CD-8595-F83362063020} - C:\WINDOWS\system32\khfCuRki.dll (file missing)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
    O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [HP Lamp] C:\Program Files\Hewlett-Packard\HP PrecisionScan\PrecisionScan\HPLamp.exe
    O4 - HKLM\..\Run: [BDRegion] C:\Program Files\Cyberlink\Shared Files\brs.exe
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Elijah Snow\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV0 2.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'c:\windows\system32\winhelper.dll' missing
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1125211609875
    O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - https://a248.e.akamai.net/f/248/5462...l/SymDlBrg.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...nt/swflash.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: uarxre.dll C:\WINDOWS\system32\tukuhegu.dll nkkznz.dll c:\windows\system32\bufozupu.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    --
    End of file - 9851 bytes


  2. #2
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    It might be a rootkit. Try running Combofix in safe mode and see if it picks up anything.

    IE should not "automatically detect settings" unless you have a proxy script running on your network. That may be what's routing your traffic to nowhere. If Combofix in safe mode turns up nothing and you're still having these problems, try resetting IE to factory defaults (its on option in there somewhere). If that doesn't work, it may just be best to format the machine.

  3. #3
    E. Body
    Join Date
    Jun 2007
    Posts
    2,065
    BG Level
    7
    FFXI Server
    Phoenix

    After getting a virus and cleaning it, I'd still reformat my computer.

  4. #4
    Bagel
    Join Date
    Jan 2009
    Posts
    1,412
    BG Level
    6

    I know losing certain registry settings (like due to a bad shutdown/RAID fail) on Windows Server OS's can cause the aforementioned issues. Reinserting the missing registry lines and rebooting usually clears it up. Never heard of that problem though in XP, usually only on servers due to the security settings they have.


    If you don't have anything of dire importance, I'd just say reformat it. Safest option.

  5. #5
    Old Merits
    Join Date
    Jun 2007
    Posts
    1,156
    BG Level
    6

    Something may still be hiding. Run Malwarebytes and see if it finds anything remaining. You may need to do a windows repair installation to fix it.

  6. #6
    Salvage Bans
    Join Date
    Jan 2005
    Posts
    871
    BG Level
    5

    Virus could have changed the windows host file.....Happened to me once.

    Using the Windows Hosts File

  7. #7
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    Delete this - O10 - Broken Internet access because of LSP provider 'c:\windows\system32\winhelper.dll' missing

    Not that it much matters. You need to run ComboFix as was stated before.

    Afterwards, go to your internet settings (control panel or via IE) and reset your security zones/pop-up blocker/privacy level/default settings to default.

    Easy!

  8. #8
    RIDE ARMOR
    Join Date
    May 2008
    Posts
    8
    BG Level
    0

    Figured I'd post here as well instead of starting a new thread. My friend brought over a computer that is infected with god knows how many crap and I'm at wit's end trying to do something, anything. He didnt wanna reformat so I gotta fix it without reformatting.

    Here's a list of the problems I have encountered:
    1. No Internet
    2. Can't open removable storage stuff( ie. flash drives, card readers, even CDs or DVDs) in safe mode. It can read stuff fine in normal bootup though. But read #5.
    4. Tried running regular antivirus which got killed as soon as I open it even when changing filename
    5. Tried to run combofix which came up with a pop up saying combofix got compromised with some virut virus so I gotta download another executable. Which I cant since internet is screwed and I cant read usb drives in safe mode and I'm thinking in normal bootup it hijacks the program and changes it or something.

    So my question is anyone ever encountered something like this and if so how to fix without reformat. Thanks for your time in reading.

  9. #9
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    Run combofix in safe mode, rename it to "combo1" or something like that so the virus can't hijack it.

    Make sure you download combofix from bleepingcomputer and NOT the first site that comes up on google.

  10. #10
    RIDE ARMOR
    Join Date
    May 2008
    Posts
    8
    BG Level
    0

    Well I guess I didnt explain enough or clarify. I cant access internet at all on that computer so I have to get combofix onto that computer with removable storage devices either by usb or cd. Now the problem when I'm booted up in safe mode, I plug in usb and nothing happens. I cant access the usb drive at all. Now when I tried to burn a CD with combofix, it would see the disc inside the cdrom with the name of the disc and everything but I cant explore the CD or access stuff on it. Now this is all within safe mode. Oh yea I did rename the file to something like combfx.exe. So without any way to run combofix, I tried booting up normally in which case I can access usb drives and CDs. So I copy combofix onto the main drive. Problem in this case is whether I run it in safe mode or after normal bootup, it pops up a msg saying combofix was modified or something with a virut virus and wont start and tells me to go to bleepingcomputer to download a clean version.

  11. #11
    Sea Torques
    Join Date
    Dec 2005
    Posts
    668
    BG Level
    5
    FFXI Server
    Valefor

    Is it feasible to pop the drive out into a different computer?

    In Safe Mode/Normal - Is it possible to pull up the Run... command and do D:\combfx.exe ?

    Are you sure the other machine is clean too?

    Can you get MalwareBytes installed on the machine (I've found the installer isn't blocked, but you'd need to rename mbam.exe to like lol.exe) and run (it won't update I bet) and run it? Many times I use MalwareBytes to do an initial cleanthrough and then use CF to hit the heavy stuff.

    Let's rock this virus. I love it when machines don't let you follow the standard plan. Rawr!

  12. #12
    Pandemonium
    Join Date
    Oct 2005
    Posts
    7,839
    BG Level
    8
    WoW Realm
    Cho'gall

    This is about the time where you'd just save more time by extracting the data and formatting the drive.

  13. #13
    RIDE ARMOR
    Join Date
    May 2008
    Posts
    8
    BG Level
    0

    lol thanks for the input but I think it's bout time I tell my friend I putting in the towel on this one. I was able to run combofix by having kaspersky installed first so it blocks the modification of combofix. The only reason I was able to install kaspersky was because of KIS 2010 since kis 2009 wont even install even when I rename the file. Maybe 2010 was too new the virus wasnt designed to kill it. I was able to download it in the first place because IE and firefox settings were both changed to be connecting through a proxy so I changed it back for that session to be able to download it. Anyway even after combofix ran through the steps twice and going through malwarebytes scanning along with kaspersky scans, the damn virut.ce virus is still there and keeps on popping up. So after a day of messing around trying everything I decided to call it quits. I havent seen a virus this advanced. Next time I just tell my friend to put in some antivirus software instead of handing it to me when it's all infected to shit.

Similar Threads

  1. Cleaning up a laptop.
    By Khamsin in forum Tech
    Replies: 10
    Last Post: 2008-05-13, 19:07
  2. Windows task manager clean up
    By BIGSTIC in forum Tech
    Replies: 10
    Last Post: 2007-02-25, 03:12