I have been chasing trojans for 2 days...

Discussion in 'Malware Help (A Specialist Will Reply)' started by MistressRene, Apr 22, 2006.

  1. MistressRene

    MistressRene Private First Class

    Hi,
    I have been chasing trojans for 2 days, then I found your site. This started with dialer.dialplatform, and adware.purityscan, and what every else comes with it. I have on my XP: Nortons 2006 AV, Spy Sweeper, Ad-Aware SE Plus, Mcafee firewall, and a few other big ones, and nothing caught this! I would kill one trojan and another would pop up, then I found this website that I thought was an anti virus site and that is when the fun started :(
    it was the one that plants the spyaxe and somewhere in there planted winlogonhook ... etc....
    ack! I then found YOUR site and used Ewido, BitDefender Online Scanner (awesome proggy!) found a few hundred files and killed 'em all!
    It seems now, maybe, all that I am left with is something hijacking my browser, 2 files that spybot S&D just found
    called ncompat.tlb and ts.ico, which I understand is from a bogus codec program called Vcodec and this winlogon.exe.
    I have run ALL my other scanners and they are all clean! I will post my latest hijack this log. Thank you in advance!
     
  2. MistressRene

    MistressRene Private First Class

    Logfile of HijackThis v1.99.1
    Scan saved at 1:09:58 PM, on 4/22/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Edit by chaslang: Inline log removed! Cleaning steps not followed.
     
    Last edited by a moderator: Apr 22, 2006
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments. You must not post any logs inline and you must complete the READ ME and attach the online scanner logs from step 6. This must be done before running HijackThis and before attach a HijackThis log.

    Read the sticky threads! They cover Winlogonhook problems and many others like SmitFraud which ncompat.tlb is part of.

    You also MUST only use one antivirus application. See step 3 of the READ & RUN ME. You have at least two installed maybe 3 if more than McAfee Firewall is installed. You also must only use one software firewall. You have McAfee but doesn't your Symantec stuff contain a firewall? It is a bad idea to mix McAfee and Symantec. Also the Windows XP SP2 firewall must be disabled if it is not already. You must resolve this before continuing.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
     
    Last edited: Apr 22, 2006
  4. MistressRene

    MistressRene Private First Class

    Hello again..
    I have a question/statement .. I only added the 1 or 2 extra virus scans after Norton as it did not do its job. No, Nortons does not have a firewall with the software I own. Yes I have MS firewall disabled. Yes I did run all of your steps way before I even thought about posting here. The BitDefender stalled out at 5 am and unfortunatly the log got overwritten. It cleaned almost of the stuff out. Over 600 files.
    I will try to use panda scan again, it would not permit me before as I have the Nortons.
    I also can not boot to safe mode, as every time I try to boot up windows asks me to check my other harddrives. The program sits and sits at 0, so I wind up rebooting and passing it by right to windows XP.

    So where should I go from here? Thanks again!
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not a good thing to do. They will just conflict with each other and slow your system down. Uninstall one. I would keep AVG.

    You are running Norton's Internet Security Suite and as far as I know it contains a firewall as part of the suite. Without the firewall it would not be a security suite.

    The READ M E clearly states to attach the two logs from step 6 and the HJT log in step 7. And it clearly indicates not to post any logs inline.

    There is no reason why Panda should not run with Norton. At least 100 users do this here per week. You may just have to give it permission to run thru Norton's script blocking.

    What sits at 0? What is 0? Do you mean the progress bar showing Windows loading? Give the exact word for word message you get. You should always give exact complete error messages.

    Note: You installed HJT here: C:\Program Files2\spywarestoppers\BHO\HiJackThis\HijackThis.exe
    While it will run from there, it is neither a spyware stopper nor a BHO.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Additional issues with running software! Too many full protections antispyware tools:
    - Ad-aware with Ad-Watch
    - Ewido
    - SpySubtract
    - Spy Sweeper
    - SpywareGuard

    Is Ad-aware the only one you purchased or did you but others? Obviously I know SpywareGuard is free!
     
  7. MistressRene

    MistressRene Private First Class

    I only now have the nortons. It is NOT the internet security, it is the Norton SystemWorks.
    I am re-running bitdefender as we speak.
    and
    Sorry, the progress bar stays at 0. I am very sleepy, only 3 hrs sleep. There were nO error messages as this was at the top of a reboot. I did, however right click to properties on each harddrive to try and force the error checking to work.


    This BitDefender stalled out again. It's prolly cause of my iSP good ole bellsouth. It was at a point where it deleted 10 more files, so I will stop it. Let windows try and do it's thing, then restart it and hopefully it wont say 10 hours left on an ADSL connection... sheesh LOL
    I'll BBL. Thank you chaslang!!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your first HJT log showed the below service:
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

    This is Norton Internet Security Suite. See the below links if you do not believe me:
    http://www.liutilities.com/products/wintaskspro/processlibrary/symlcsvc/
    http://www.auditmypc.com/process/symlcsvc.asp


    So what happened.


    OKAY! Skip Bitdefender and PandaActveScan and run the below scans instead and then attach the Ewido log. Since you already had Ewido installed, you can skip the install part but make sure you have the updates:
    Running Ewido Anti-Malware

    Also since you have Spy Sweeper currently install make sure you have the current updates and get a log from it too per the below;

    Running Spy Sweeper
     
  9. MistressRene

    MistressRene Private First Class

    ok here we go. 1st I would like to address the file called symlcsvc.exe. What that actually is, in Norton SystemWorks is the control panel that shows all of the SystemWorks are working correctly. (btw: symlcsvc.exe also can show as a BHO according to those sites. I will re check the registry tomorrow) I do NOT have a Norton firewall on my machine.
    Now for da meat LOL ...
    I finally got the checkdsk to work with that force. It was my D drive that needed attention. All is well now :)
    I ran the ewido and the spysweeper, and they both show clean YEA! but...something is still hijacking my IE6 browser, as my real homepage is http://www.google.com/ NOT the http://securityresponse.symantec.com/avcenter/fix_homepage/
    After all this is done, the 'new' scanning proggys that I downloaded will be removed.
    OH one more item... in the original HJT log, I did not have the msconfig set to 'normal'. I had it at selective. I do now have it fully loaded.
    Once again, thank you sooooo much chaslang! :)
     
  10. MistressRene

    MistressRene Private First Class

    I'm not sure I did thie correctly, I need zzzzzz's
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O15 - Trusted Zone: http://stats.adultrevenueservice.com
    O20 - Winlogon Notify: winqsc32 - winqsc32.dll (file missing)
    After clicking Fix, exit HJT.

    Then reboot and take a look a new HJT log and make sure that those lines did not come back.

    Other than that your clean.

    Are you have any malware related issues?
     
  12. MistressRene

    MistressRene Private First Class

    Afternoon all!
    Today is a much better day than the past 2. I also wanted to let you know that I added the http://stats.adultrevenueservice.com to the trusted zone as I do business with them (couldn't check my stats). One of the host files as I finally found out was blocking them and some others that I use. I no longer need it now in the zone, since I know how to fix it :)
    --
    All programs are now showing 100% clear, BUT.....(there is always a butt)..My IE homepage is STILL being hikacked to
    http://securityresponse.symantec.com/avcenter/fix_homepage/ of all things. My normal homepage is http://www.google.com . I have tried changing it in the registry, where ever that symantec URL is, I changed it. I tried changing it in spysweeper too, and as soon as I close the tools/internet options/homepage menu and hit homepage in IE it reverts back to the symantec URL. We are missing something here (scratchin head!).

    I also would like to know what is recomended by you to clear wayward entries in the registry? There have been a few proggys that have come and gone, and I know there are still traces that have not been removed.

    and lastly... I want to say a big {{{ THANK YOU }}} to chaslang for being such a super and patient help to me. I have been on computers/net since 1997 and this was my very 1st virus ever ... and hopefully my last! So again.... thanks!
     
  13. MistressRene

    MistressRene Private First Class

    ps:: I just tried, "amust registry cleaner" the online scanner, and there were a few things that needed to be removed, but these stands out...
    Invalid Program Identifier: context.text
    Invalid Program Identifier: context.text.1

    and especially this???
    Invalid Program Identifier: Symantec.NavSniff.1
     
  14. MistressRene

    MistressRene Private First Class

    hummm...
    something new just came up. I was doing a bit of work, and heard the XP "error sound" I went to look in the administrative tools, and under event viewer/system/ There were entries from Windows Defender, all this afternoon saying that the HOST FILES had a problem.
    there are about 10 entries most with different numbers inside the { }.
    Here is a very short summery of what it says:
    Event Type: Warning
    Event Source: WinDefend
    Event Category: None
    Event ID: 3004
    Date: 4/23/2006
    Time: 3:44:36 PM
    User: N/A
    Computer: THEBEAST
    Description:
    Windows Defender Real-Time Protection agent has detected spyware or other potentially unwanted software.
    Scan ID: {3C652FF4-C297-438E-A32A-D1BC6AC19065}

    OR

    Event Type: Information
    Event Source: WinDefend
    Event Category: None
    Event ID: 3005
    Date: 4/23/2006
    Time: 3:40:10 PM
    User: N/A
    Computer: THEBEAST
    Description:
    Windows Defender Real-Time Protection agent has taken action to protect this machine from spyware or other potentially unwanted software.
    Scan ID: {A18E7E9B-27BF-473B-9610-16B5B3E6217F}
    They seem to altername for about 10 or so times since noon today.
    WindowsDefender found this too:
    I wish they had a dern log :(
    Im typing this next thing longhand:
    Resources:
    ie main:
    HKCU@S1-5-21-1085031214-706699826-1343024091-1004\SOFTWARE\Microsoft\Internet Explorer\Main\\SearchBar

    Should I change my host files just to reflect 127.0.0.1 with NO sites listed?
    I can't type anymore..thanks again!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember when I said the below in a previous message:
    Having all these running can make it impossible for you to control what you want be cause they will all block each other. And you also have Windows Defender making even more problems if you still have all of these. Your problem is not malware it is too much goodware. Uninstall all but one (I would keep only Spy Sweeper)! And then change your pages and just make sure you tell Spy Sweeper to allow the change.

    Unless you are an expert, you really must be careful playing in the registry. And you should backup your registry first. There are many tools in the below link for editing and backing up the registry. It depends on exactly what you are looking to do.

    http://www.majorgeeks.com/downloads15.html

    I like Registrar Lite for many things and you will see it used a lot in the threads here.
    Also like Erunt for backups!
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    My hosts file is always set to the system default and I never need it to be anything else.

    The easy way to set system defaults for all PCs is below:

    Download HOSTER and then follow the below steps.
    • Unzip Hoster to a convenient folder such as C:\Hoster
    • Run Hoster.exe, click Restore Original Hosts and then click OK.
    • Click the X to exit the program
     
  17. MistressRene

    MistressRene Private First Class

    I uninstalled all but the ones I paid for, webroot spysweeper, and adaware. The rest are either free ware shareware that I got for this specific purpose. They all did have their own special function.

    I have been playing mildly in the registry since 1997. If anything major has to be done I don't touch it. So far I have not had THAT kind of problem whew!
    I will look into the reg. programs that you recommend, thanks!


    These are strange!

    My anti-spyware programs made my host file an abortion. I wanted to get it back to the default. I just did it and it is now default.. kewl. now I can check my stats! LOL

    I am going to end this on a wonderful note...
    I was able to finally get into safe mode YIPEE! I was able (keep fingers xx'ed) to get my homepage to stick!
    thank you thank you thank you! :D
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are going to use Spy Sweeper you should consider not using Ad-watch from Ad-Aware. They could fight each other.

    Spy Sweeper will add a load of stuff to the hosts file to block various sites. Personally I find this to be a bad thing to do and disable that feature of Spy Sweeper. Adding lots of things to the hosts file makes it too easy for bad stuff to hide in the long list. Having the hosts file at default makes it obvious when malware has added itself.

    Without seeing full registry key path information on the those keys you mentioned, I cannot comment on them. The one from Symantec could be a left over from an active-x object due to using an online scan from them at one time. It could be related to any of the below:
    O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
    O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - https://www-secure.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
     
    Last edited: Apr 24, 2006
  19. MistressRene

    MistressRene Private First Class

    That is exactly why I needed the default HOST! It took me 4ever to figure out what was preventing me from accessing some of the sites that I deal with. I went back and forth with webroot too. They were as useless as t*ts on a boar. LOL I finally saw that when I clicked the host files in ss the host files changed, so I just kept it unclicked and delete the addresses from the host file.
    I JUST renewed my subscription with them too ... OH WELL

    This was a very interesting weekend for me, and I have learned alot. Not the most fun at all but interesting!
    Thanks again chaslang! This is going to be my last post as I scanned this AM and I am totally clean :)

    ciao!
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't get my comments wrong! Spy Sweeper is great overall. I just don't like that feature but some people do. I don't find it to be worthwhile for the reason I mentioned and there are free tools for adding thousands of lines to the hosts file. This actually slows down your surfing performance too. Actually Spy Sweeper is first on my list when it comes down to which program I recommend the most for blocking and removing malware.
     
  21. MistressRene

    MistressRene Private First Class

    I like SS better than adaware. The big A used to be great, but its lost its UMPH this past year. Their support forum disappeared too. They used to post where on your site (lol) where to find the new ref files and sites.txt. No more OH WELL...
    boy it sure is nice being able to run around the web quickly yipeeeeeeeeeee!
    May I ask you a personal question??? You don't have to answer if you dont want to LOL ... How old are you?
    The reason I ask is cause teenaged geeks make me go nutz. I'll talk to them on the net and they will talk geekspeak and then they say "I'm 14 years old" ... DOH! It's to funny.

    OH I think I found out what the sniffer thingy is: That new home page that was created from symantec referred me to a certs page:
    http://www.cert.org/tech_tips/win-UNIX-system_compromise.html

    there is a link on that page that referrs to another page, where this is:

    Look for signs of a network sniffer
    When a system compromise occurs, intruders could potentially install a network monitoring program on UNIX systems, commonly called a sniffer (or packet sniffer), to capture user account and password information. For NT systems, remote administration programs would be more commonly used for the same purpose.
    The first step to take in determining if a sniffer is installed on your system is to see if any process currently has any of your network interfaces in promiscuous mode. If any interface is in promiscuous mode, then a sniffer could be installed on your system. Note that detecting promiscuous interfaces will not be possible if you have rebooted your machine or are operating in single user mode since your discovery of this intrusion.

    Interesting :)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    They opened their forum up to the public again, and we still have downloads for their files here on MGs.

    Ad-Aware was never as good as Spy Sweeper. It was a nice "free scanning" tool but it never typically found and fixed anything of great significance like Spy Sweeper has always done. I personally think it is a big injustice wasting so much time and scaring users by reporting MRUs and cookies.

    I'll never tell but with a little searching thru the forums and lounge threads you could get some hints! :D But I'm not a teenager! Which my Profile page would indicate to you......but who can trust what they read on a Profile page.:) But I'm old enough to have heard of websites with MistressRene getting hits in a search. Any relationship?


    You do not have any packet sniffer software installed. They are referring to things like Ethereal and WinPCap, IP Sniffer, NetworkActiv Sniffer 1.5.1 (for a few examples).
     
    Last edited: Apr 24, 2006

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds