nasty virus or trojan?

Discussion in 'Malware Help (A Specialist Will Reply)' started by Peregrine, Nov 26, 2006.

  1. Peregrine

    Peregrine Private E-2

    Hi,
    First of all, I did follow the READ & RUN ME FIRST thread, so hopefully I've gathered all the information you need.

    History
    This is a brand new HP PC picked up a week ago by a friend of mine from the store. I installed some extra software for her, but nothing that would create the following problems. Everything worked perfectly when I gave it to her last weekend. Yesterday, she brought it in with a "sound problem". I started checking the sound, and it seemed ok at first, but then the hell got lose...

    Problems
    Everything seems to be working fine for about a minute after the user logs in. After that the firewall service is totally disabled. The Wireless Network Connection panel reports that another program is controlling functions to choose a wireless network, and that the WZC service needs to be started. It's set to automatic, but it doesn't start automatically. When I start the service, the panel then allows to choose a network, but after connecting, it can't automatically set an IP that NAT is assigning it from my router, so the connection is limited. Manual IP renew doesn't work. I tried the NETSH WINSOCK RESET command several times, and it worked fine... for a minute after the system was rebooted and I logged in. Device manager shows no problems, although "Scan for new devices" option is gone. But Skype reports there are no sound devices installed. The sound on the PC sometimes works and sometimes doesn't. I would reinstall the driver, but this is pointless, since EVERYTHING from the above works fine initially, and then all the problems kick in at once. I'm sure there are other symptoms, but this is enough for me to treat this as a virus/torjan issue. I've run a procedure to even reset configuration of WMI, all to no avail.

    Antivirus/antispyware progress
    Before I even found this forum, I've run Spybot S&D, Lavasoft Ad-aware, and McAfee antivirus scans several times, all reports running smoothly and indicating no major problems (minor cookies, etc).
    Then I did everything from the READ & RUN ME FIRST thread, and all the antivirus/spyware/malware tools reported nothing major, if anything at all.
    I've collected all the logs, in which I can't find anything, but then again, I don't have much experience searching for trojans in logs.
    :rolleyes:
    I would really appreciate your help on this.
    Files are attached.
    Thanks
     

    Attached Files:

  2. Peregrine

    Peregrine Private E-2

    remaining files are attached
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    Sorry but you are in the wrong forum. Your problems are not due to malware but are rather due to something you installed, tweaked, configured etc since taking the PC out of the box. Possibly due to installing things like the below CRACK which was found by Panda.

    Possible Virus. Not disinfected C:\Program Files\Common Files\Microsoft Shared\OFFICE11\Anti-MSOPA.exe[Anti-MSOPA.exe]

    My recommendation would be to use GoBack (which seems to be installed or System Restore) and set the PC back to how it was shipped. Then be more careful what you install and configure.
     
  4. Peregrine

    Peregrine Private E-2

    since I'm using GoBack, System Restore is turned off. And GoBack doesn't hold history for longer than few days. If it is one of the cracks I installed, then apparently it must be a virus/trojan that is residing on the PC.
    There is no way to back out, so can you tell me anything more that may be causing the problems?
    Thank you.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How many cracks did you install?? No it is not a visible problem of any form with malware. It is due to whatever you have done on the PC. If you do not have System Restore and GoBack does not go back far enough, then just use the system recovery disks that came with the PC and set it back to the way it was delivered. Since it is only a week old there can't be much user data needing backup or anything else to important. This time don't do whatever you were doing.

    Another option would be to just try uninstalling everything you installed and see what happens. Perhaps you will get luck!
     
  6. Peregrine

    Peregrine Private E-2

    well, I was able to find one active virus, through Spybot's report of working processes: System32.exe. I removed that, but it didn't help anything. Then I stumbled upon this info: http://windowsxp.mvps.org/sharedaccess.htm and I used "sharedaccess.reg" to rebuild the registry, then reset the winsock. After that everything started working like a charm. Everything worked perfectly for 2 days - 1 day while I was doing minor improvements and cleanups, another day when she picked it up and took it home. But today she just called me again and told me the same thing happened...
    Now I'm totally buffled...
    I can now of couse easily revert using GoBack, but why is this happening, seems like only where she's using the coputer?... BUt she's also behind a secured NATed router, so I doubt anyone's actively exploiting that computer...
    Not when it's behind the router...

    The only thing I can think of is another anomalie I wasn't able to fix nor figure out, and maybe that is the key to the cause of these problems as a vulnerability:
    Ever since the last MS updates I did on that computer 2 weeks ago, there was one last piece called MXML SP2 security patch (or something similar - I don't remember right now and don't have that coputer here yet). Every time this patch would be reported as installed (either through MS Update's engine, or through the automatic updates running process), and even though it's reported as installed, and it is residing as installed in the list of programs, automatic updates process keeps repeating the process, as if it sensed that this particular patch was not installed. The MS Updates engine (their website) does the same thing, whenever I go to check for updates, it always shows and installs this one. I even downloaded that file manually from MS support site and reinstalled it (although without removing it) myself, so I know it's installed. But somehow the MS verification routine does not see it as installed...
    Would this constitute and type of vulerability through which all these problems may be caused?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That must have been a new problem because it did not show in newfiles.txt. Either that or the file had a date that was more than a year old so it would hide from programs like ShowNew that look for new files. But then one of the antivirus applications should have easily found it especially if it tried to run.

    I doubt this is the problem.
     
  8. Peregrine

    Peregrine Private E-2

    I'm not sure. I ran all antivirus applications and collected the logs on monday, and then didn't touch that laptop 'til friday, so it was turned off. On friday I found that system32.exe when I was looking through spybot's running processes list. Once I removed it then, I've not seen it come up after that.

    So to give a little up to date status, after she brought it back to me again, I rebuilt the registry and reset winsock again, but this time I also cleared GoBack history (totally, by disabling it, and after fixing everything, I enabled it back). System restore is not an issue, since it's turned off, because it's a redundant service when GoBack is installed. She took the PC back and it was working fine for few days, then the problem came back. But about an hour ago she called and said that ever since yesterday, everything is working like a charm...
    Go figure...
    It sounds less and less like a virus or trojan. Maybe it was just a weird MS issue that they finally took care of by an update.
    I just hope the problem will not come back.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well sometimes it is end user problems and not malware! ;)

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds