This Virus Has Me Miffed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by steelo121, Jul 3, 2005.

  1. steelo121

    steelo121 Private E-2

    Hey guys,

    First and foremost, thanks for all the help you've given everyone, and for any help I receive in advance. Here's a brief history of all the things I've done to try and fix the problems on my computer. I reinstalled XP about two weeks ago, and as soon as I connected to the net, I got all of these alerts saying there was spyware on my computer, all of which were telling me to go to these ridiculous URLs. They eventually caused my computer to shut down because of an error caused with the LSA shell. When I sent an error report to microsoft.com, it said I had a variant of the sasser virus, so I downloaded the sasser fix from the symantec site, which solved the shutdown problem. I also updated my antivirus software, downloaded the service pack 2 for XP, and ran ad aware and spybot.

    I thought all was well and good, until I realized that whenever I hit ctrl+alt+delete to bring up the task manager, the task manager wouldn't show up. Then I tried running tasklist through the run toolbar, but tasklist closes within a second of opening. Also, programs would crash very easily, with simple things like just trying to save an image. Installing new programs was nearly impossible as well. Whenever I went to right-click on the connection icon to disconnect from the internet, the program would not disconnect. I'd shut down my computer, come back to it later and restart, then go online, and my anti-virus software would catch a registry file from a LowZones virus. This would happen EVERY time connected to the internet! No matter how many times my anti-virus software caught the file and I deleted it, it would always be back. It can't be because of system restore, because I made sure to turn that off. None of these symptoms would come up until I attempted to connect online.

    I got so annoyed by the whole thing that I reformatted the drive in an attempt to get rid of the virus, but it survived the reformat! I had to go through the whole process all over, just to keep my computer from crashing because of an LSA error. I still have all of the symptoms I mentioned in the last paragraph, in addition to my anti-virus software catching an occassional spybot file. Oh, and also, whenever I restart my computer, my computer immediately tries to connect online to receive information from sites.

    I followed the read me file you posted in the forum, and still have the problems. I need help... desperately. Is this some sort of blended threat? My anti virus has diagnosed the files as sasser, spybot, and LowZones. Please help!
     
  2. steelo121

    steelo121 Private E-2

    I forgot to mention that the name of the file found by my symantec anti virus whenever I sign online is "kans.reg", without the quotes. It tries to appear in "C:\temp". The virus name is "Trojan.LowZones!reg", again, without the quotes. Please help. :(
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We have procedures in this forum that need to be followed and you should read them along with people who are requesting help. Please read the sticky threads. Also please do not post external links to software downloads when they are available here on MGs.

    And one final comment, defragmenting a drive does not recover lost files. It rearranges files on your hard disk to make the space they take up contiguous.
     
    Last edited: Jul 3, 2005
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    steelo121,

    Here are the proper steps to follow. (note: the kans.reg file is a registry patch and is part of your problem. It is probably located in a temp folder. We should find it thru the below processes.)

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps below:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. steelo121

    steelo121 Private E-2

    As requested, I have attached the Hijack This log to this thread. I followed all of the steps you mentioned beforehand in the other thread, except for the last online scan because it refused to open, no matter how lond I waited.

    Here are a couple more notes about the virus. As you mentioned, the "kans.reg" file was stored in a temp file. There is a file called update.htm in the same folder that it tries to redirect my browser to, but my anti-virus software stops that. No matter how many times I erase them, they reappear. Also, every now and then, the software also detects a "TFTP....." file, with the letters followed by random numbers. I did a search for 0 byte TFTP files by typing tftp*.* in the search toolbar and found a couple of them, and also a couple of other ones that I didn't erase because there weren't 0 bytes, and I was being cautious. I looked in the WINDOWS\Prefetch folder and found a couple of suspicious files. One was a TFTP file, as well as a few files named "ERASEME.....", with the letters followed by random numbers as well.

    Thanks for all the help again!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your Windows OS and IE version are way out of date and represent a major security risk. You must get updated after we finish fixing any remaining problems you have. We will discuss that later.

    Firefox should not be running when you use HijackThis. It is a browser. All browsers should be closed.

    You have a couple of worms. One is Troj/Crater.A . See: http://www.sophos.com/virusinfo/analyses/trojcratera.html for info on it and some of the files it may have put on your PC.

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    On the page that opens, scroll down to Net Functions Library or Netlib Then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Now repeat the above for: Windows Process Moniter

    Next, open up HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    Net Functions Library

    If that does not work, use the short name: Netlib
    Now repeat the above HijackThis steps for: Windows Process Moniter

    At this point it may ask you to reboot your PC. So reboot and then get a new HijackThis log to post and tell me how things are working.

    If the below are still in your HJT log, it means the above steps did not completely work:

    O23 - Service: Net Functions Library (Netlib) - Unknown owner - C:\WINDOWS\System32\Netlib.exe
    O23 - Service: Windows Process Moniter - Unknown owner - C:\WINDOWS\winmon.exe
     
  7. steelo121

    steelo121 Private E-2

    I did as you instructed and posted the log. When trying to stop the Net Functions Library, an error occurred saying that it could not be stopped because it did not end in a timely fashion, or something to that nature. I was able to disable it at startup and delete it using Hijack This!. As for the Windows Process Moniter, it didn't even give me the option to stop it, but I was able to disable it at startup and delete it as well. The lines you mentioned in the previous reply no longer appear in the log.

    However, I did already encounter a problem that leads me to believe that the virus still lingers. While I was trying to post this log the first time around, firefox froze while I was uploading the log file. Then when I went to bring up the task manager, I hit ctrl+alt+delete, and the task manager window didn't come up. Both were things that were happening before.

    Thanks again for all your help, and I'm eagerly awaiting the next set of instructions.
     

    Attached Files:

  8. steelo121

    steelo121 Private E-2

    Yeah, the problems bringing up task manager are constant. Also, the tasklist window shuts down immediately when I try to bring it up with the run toolbar.
     
  9. steelo121

    steelo121 Private E-2

    My anti-virus software just caught a file named "eraseme_37458.exe", so I guess this stupid thing is still in there. I did a search for files titles eraseme, and found a couple more. Should I erase these?
     
  10. steelo121

    steelo121 Private E-2

    What's happening?!?!?!?!?! As I was online, my anti-virus software caught ANOTHER "kans.reg" file. When I took another Hijack This! log, winmon.exe was back, and there was another suspicious file. What's going on?! I thought I got rid of these. I feel like the more I do, the worse things get.
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Remember my comment from a few messages ago:

    Your Windows OS and IE version are way out of date and represent a major security risk.

    That's the root of all your problems. That and the fact that you have no firewall and probably insufficient protection.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also (along with winmon) you know have a worm added by the W32/Codbot-M worm and IRC backdoor trojan.

    C:\WINDOWS\System32\netddeclnt.exe

    Boot into safe mode and stop the above process if running and then delete the file.

    Delete winmon like before.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  14. steelo121

    steelo121 Private E-2

    I did everything you instructed me to do. All seems well right now. Task manager now seems to be working fine, and no weird freezes. The only odd thing left is that tasklist still won't open.

    Also, right before I was going to submit this, I got a message from my firewall that said this:

    Generic Host Process for Win32 Services (svchost.exe) is being contacted from a remote machine [207.217.77.82] using local port 1129. Do you want to allow this program to access the network?

    I chose no, but didn't set this to do it all the time. It seemed fishy to me, but I don't know if I'm being too cautious.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That IP belongs to your ISP (I assume) Earthlink. You should ask them why they are trying to access your computer because that port is also used for malware attempts. See: http://securityresponse.symantec.com/avcenter/venc/data/backdoor.anyserv.b.html

    and also: http://www.sophos.com/virusinfo/analyses/trojagentaa.html

    I would deny it and always use the same setting for now.

    Post a new HJT log. Are you saying you can open Task Manager but the Processes tab does not show?
     
  16. steelo121

    steelo121 Private E-2

    When I was talking about tasklist, I meant typing tasklist in the run window. It closes immediately. Everything else seems to fine, but I did get another odd message from my firewall that I denied:

    NDIS User mode I/O Driver (ndisuio.sys) has receive a packet from the remote machine. Do you want to allow this protocol driver to access the network?

    This alert came up as soon as XP booted up.

    I also attached my HJT log again.
     

    Attached Files:

  17. steelo121

    steelo121 Private E-2

    Wait, is tasklist SUPPOSED to close so quickly? If so, my mistake.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is! If you want to see processes it is easier to use Task Manager!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're log is clean. Now you need to get your Windows update ASAP. Complete the steps in the below thread (the first step is Windows Update):

    How to Protect yourself from malware!

    You do not need to give NDIS User mode I/O Driver access to the network but it is a valid system process.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds