Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Found Win32 Trojan KillProc but more?
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Found Win32 Trojan KillProc but more?  
Forum Quick Jump
 
New Topic Post reply to : Found Win32 Trojan KillProc but more? Printable version of : Found Win32 Trojan KillProc but more?
[ << Previous Thread | Next Thread >> ]

DRocK
New Member


Date Joined Jan 2008
Total Posts : 4
 
   Posted 1-23-2008 2:22 (GMT +2)    Quote: Found Win32 Trojan KillProc but more?Alert an admin about: Found Win32 Trojan KillProc but more?
What made me notice that something was wrong was when I tried to download the latest World of Warcraft patch and I couldn't connect to the server.  Made sure the ports used to do this were opened, tried firewall on/off, made sure ports were opened on my router (Linksys).  Noticed my Norton was disabled.  Couldn't restart it.  Was confused... ran trusty AdAware.  Couldn't upgrade the definitions file.... weird.  Ran it and found tracking cookies and "Win32.Trojan.KillProc".  Removed it.  Rebooted.  Can connect to the internet but still seem to have blocked ports or programs or something.  WoW still won't connect.  Installed "Kaspersky Anti-Virus 6.0 SOS", but get same error as trying to run Norton "C:\..... filename.exe" is not a valid Win32 application".  Other exe's seem to be working.  Install AVG Anti-Spyware 7.5... run and get "Connection to service failed.  Please reinstall AVG Anit-Spyware 7.5".
 
All the while I can't find any running processes that look abnormal.  Googled em all and linked them to a program that should be running.  Ran Trend Micro's Housecall thinking I could dodge having to use an exe... and it found "Worm_Spybot.HM" in 2 places.  Cleaned them... restarted... but problem still presists.  Can't run Anti-Virus software.  Can't upgrade AdAware def. files, can't patch WoW (which is the big one =), can't run Norton or any other Antivirus .exe that I've tried.
 
Could damage have been done to windows xp in the removal of the two viri?  What would you do next?
 
Also just thought of one more thing.... I'm guessing whatever I picked up was off P2P file trading.  The folder that the files go to is "C:\Down".  This folder is now invisible.  I swear I didn't do it.  It's not "hidden" but is curiously "read only".... As in windows exploer doesn't see it... but I can browse to it through command prompt or if I type "C:\Down" in the address bar.  Also tried to delete it from command prompt... and it looked like I was victorious, but it's still there...
 
Help?
Back to Top
 

DRocK
New Member


Date Joined Jan 2008
Total Posts : 4
 
   Posted 1-24-2008 5:28 (GMT +2)    Quote: Found Win32 Trojan KillProc but more?Alert an admin about: Found Win32 Trojan KillProc but more?
Help?!?  Or will it be easier to reinstall everything?  Curiously... I can't even get into safemode.....
 
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 8:33:06 AM, on 1/24/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Compaq_Administrator\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://thottbot.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PRESARIO&pf=desktop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - c:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Startup: Norton Internet Security.lnk = ?
O8 - Extra context menu item: Save with Download Manager... - C:\Program Files\J River\Media Jukebox\DMDownload.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
--
End of file - 6847 bytes

Post Edited (DRocK) : 24-01-2008 15:35:24 GMT

Back to Top
 

DRocK
New Member


Date Joined Jan 2008
Total Posts : 4
 
   Posted 1-24-2008 10:58 (GMT +2)    Quote: Found Win32 Trojan KillProc but more?Alert an admin about: Found Win32 Trojan KillProc but more?
ComboFix 08-01-23.2 - Compaq_Administrator 2008-01-24 8:38:16.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.572 [GMT -7:00]
Running from: C:\Documents and Settings\Compaq_Administrator\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\_000003_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000009_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\_000014_.tmp.dll
C:\WINDOWS\system32\drivers\srosa.sys
E:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_SROSA
-------\srosa


((((((((((((((((((((((((( Files Created from 2007-12-24 to 2008-01-24 )))))))))))))))))))))))))))))))
.

2008-01-24 08:37 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-22 14:17 . 2008-01-22 20:39 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-01-22 13:58 . 2008-01-22 13:58 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-22 13:58 . 2008-01-22 13:58 <DIR> d-------- C:\KAV
2008-01-22 08:00 . 2008-01-22 08:00 <DIR> d-------- C:\Down2
2008-01-20 15:39 . 2008-01-20 15:39 <DIR> d-------- C:\Music
2008-01-18 22:17 . 2008-01-18 22:17 <DIR> d-------- C:\Program Files\Lavasoft
2008-01-18 22:16 . 2008-01-18 22:16 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-18 21:51 . 2006-03-15 02:04 749,637 --------- C:\WINDOWS\system32\drivers\hldrrr.exe
2008-01-18 21:46 . 2008-01-18 21:46 <DIR> d-------- C:\WINDOWS\system32\drivers\down

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-24 15:22 --------- d-----w C:\Program Files\World of Warcraft
2008-01-23 03:00 --------- d-----w C:\Program Files\Google
2008-01-23 03:00 --------- d-----w C:\Program Files\GemMaster
2008-01-23 00:09 --------- d-----w C:\Program Files\eMule
2008-01-17 00:25 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-12-31 03:40 --------- d-----w C:\Program Files\Quicken
2007-12-21 18:16 --------- d-----w C:\Program Files\Trillian
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 09:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [ ]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"ftutil2"="ftutil2.dll" [2004-06-07 14:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-13 20:05 16239616 C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-02 16:19 77312 C:\WINDOWS\arpwrmsg.exe]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 15:14 237568]
"PCDrProfiler"="" []
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-01-24 08:40 52848]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 15:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-16 23:11 49152]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 SOS\avp.exe" [2008-01-24 08:40 231952]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 02:25 6731312]

C:\Documents and Settings\Compaq_Administrator\Start Menu\Programs\Startup\
Norton Internet Security.lnk - C:\Program Files\Common Files\Symantec Shared\NMAIN.EXE [2005-09-17 00:27:16 824944]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
"EnableLUA"= 0 (0x0)

SafeBoot registry key needs repairs. This machine cannot enter Safe Mode.

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\File system]
@="Driver Group"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vgasave.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E967-E325-11CE-BFC1-08002BE10318}]
@="DiskDrive"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96A-E325-11CE-BFC1-08002BE10318}]
@="Hdc"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96B-E325-11CE-BFC1-08002BE10318}]
@="Keyboard"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96F-E325-11CE-BFC1-08002BE10318}]
@="Mouse"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318}]
@="System"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{71A27CDD-812A-11D0-BEC7-08002BE2092F}]
@="Volume"


*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-01-19 04:36:52 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - Compaq_Administrator.job"
- c:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 08:44:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Back to Top
 

DRocK
New Member


Date Joined Jan 2008
Total Posts : 4
 
   Posted 1-25-2008 5:45 (GMT +2)    Quote: Found Win32 Trojan KillProc but more?Alert an admin about: Found Win32 Trojan KillProc but more?
thanks for all your help! visitors, don't bother with this site... I havn't heard a thing in 3 days
Back to Top
 

Ninjuhh
New Member




Date Joined Jan 2008
Total Posts : 14
 
   Posted 1-25-2008 8:37 (GMT +2)    Quote: Found Win32 Trojan KillProc but more?Alert an admin about: Found Win32 Trojan KillProc but more?
DRocK
You posted those yesterday.
Not 3 days ago.
People on here are busy...

And visitors, the people on this site, helped me
with virus's numerous times.
Back to Top
 

Ninjuhh
New Member




Date Joined Jan 2008
Total Posts : 14
 
   Posted 1-25-2008 8:42 (GMT +2)    Quote: Found Win32 Trojan KillProc but more?Alert an admin about: Found Win32 Trojan KillProc but more?
Also, have you read Before Posting Log  ?
Back to Top
 
New Topic Post reply to : Found Win32 Trojan KillProc but more? Printable version of : Found Win32 Trojan KillProc but more?
 
Forum Information
Currently it is Friday, September 05, 2008 7:24 PM (GMT +2)
There are a total of 61.804 posts in 15.428 threads.
In the last 3 days there were 19 new threads and 61 reply posts. View Active Threads
Who's Online
This forum has 26353 registered members. Please welcome our newest member, mysterious_.
37 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Choose you like (0)05-09-2008 16:31:25 (cheap air jordan)
Removal of download misleadapp -what to do with hijackthis log- (8)05-09-2008 13:19:11 (selflerner)
ROOTKIT PROBLEM, HELP PLEASE (5)05-09-2008 12:44:35 (glass chameleon)
Google redirect virus and others (0)05-09-2008 12:02:53 (k12k)
A lot of malwares and now my laptop don't run (1)05-09-2008 11:05:23 (Touch)