HJT, BD, PAS logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by TcatMG, Apr 29, 2006.

  1. TcatMG

    TcatMG Private E-2

    I've been through the steps. Just not sure if computer is cleaned of Trojan, so I didn't run "Step 1" yet (Disable Restore). So far nothing bad happening (was getting lots of NAV scanning windows popping up). Logs attached. All except HJT run in safe mode, should I run anything more in normal mode?

    Thanks for the help! This site is fantastic!
    Tom
     

    Attached Files:

  2. TcatMG

    TcatMG Private E-2

    After reviewing and searching for info, the items that look suspicious to me on the above HJT log are (should I hit "fix" in HJT?):

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
    C:\WINDOWS\system32\wuauclt.exe

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O17 - HKLM\System\CCS\Services\Tcpip\..\{D0C1A0FB-B5F2-4108-9E3D-968F013C7ED3}: NameServer = 209.116.241.10,216.99.225.31,216.99.233.253
    O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe

    Thanks,
    Tom
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No!! Most of those are valid!

    Only these should be fixed:
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
    O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)

    However the below are all relate to the rootkit Sony took tons of critcism for installing on PCs all over the world.

    C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe

    O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
    O23 - Service: XCP CD Proxy (CD_Proxy) - Unknown owner - C:\WINDOWS\CDProxyServ.exe

    Read the below for additional info on this rootkit:
    http://www.bleepingcomputer.com/startups/$sys$DRMServer.exe-13347.html
    http://www.bleepingcomputer.com/forums/topic34904.html

    They also explain how to remove it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds