Forum Index

It appears you have not yet registered with our community which limits what you can do & see. It's Free To register, please click here.





Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #11  
Old 01-08-2005, 04:42 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
One more thing. Ctor.dll is related to hotbar adware so click here with internet exolorer and run the scan as it detects that file..http://www.spyware911.net/xcleaner.htm
Reply With Quote
  #12  
Old 01-08-2005, 04:55 PM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
Okay then, here are the "Findit" results:

Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32

01/08/2005 10:32 AM <DIR> dllcache
01/08/2005 12:21 AM <DIR> Microsoft
0 File(s) 0 bytes
2 Dir(s) 18,280,923,136 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32

01/08/2005 10:32 AM <DIR> dllcache
01/08/2005 12:20 AM 749 wuaucpl.cpl.manifest
01/08/2005 12:20 AM 749 cdplayer.exe.manifest
01/08/2005 12:20 AM 749 sapi.cpl.manifest
01/08/2005 12:20 AM 749 nwc.cpl.manifest
01/08/2005 12:20 AM 749 ncpa.cpl.manifest
5 File(s) 3,745 bytes
1 Dir(s) 18,280,919,040 bytes free

---------- Files Named "Guard" -------------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32


--------- Temp Files in System32 Directory --------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32

03/25/2003 05:00 AM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 18,280,919,040 bytes free

---------------- User Agent ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform]


------------ Keys Under Notify ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c, 00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c, 6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c, 6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c, 6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c, 6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEven t"
"Logoff"="UnregisterTicketExpiredNotificationEvent "
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


---------------- Xfind Results -----------------


-------------- Locate.com Results ---------------


C:\WINDOWS\SYSTEM32\
cdplay~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
ncpacp~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
nwccpl~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
sapicp~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
wuaucp~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K

5 items found: 5 files, 0 directories.
Total of file sizes: 3,745 bytes 3.66 K

Reply With Quote
  #13  
Old 01-08-2005, 05:03 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
That logfile as well as the previous are clean as a whistle...Try an independent virus scan from here maybe because nothing is showing up except this:
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
Then reset the homepage..and reboot.
Reply With Quote
  #14  
Old 01-09-2005, 12:06 AM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
Okay then, after numerous attempts to run various online virus scanners, Adaware, Ewido security suite and Tauscan, they all hang up and die (two of them hung up on MSADO15.dll at 1% of the scan, then hung the whole system up). I'm wondering if you have any advide on detecting and/or removing rootkit type invasions?
Reply With Quote
  #15  
Old 01-09-2005, 12:15 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Try updationg the version of that file by downloading and replacing with this http://www.dlldump.com/cgi-bin/downloadcou...s/M/msado15.dll. Be sure however to copy and paste the current file so it can be placed back if need be..
Reply With Quote
  #16  
Old 01-09-2005, 10:45 PM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
Well, when I tried copying the new msado15.dll the whole system froze just upon trying to execute a right click copy command. I rebooted and downloaded and installed Microsoft's new version of what used to be Giant Antispy (or something like that). It reported finding SearchSquire Adware installed with the following keys:
Infected registry keys/values detected
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\ZoneMap\Domains\searchsquire.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\ZoneMap\Domains\searchsquire.com * 4

I then rebooted this morning with a BART's pe disk made from a clean machine last Thursday. After running several scanner with nothing reported, I ran a rather complete, almost 8 hour Tauscan from the disk and found the following:

Tequilla Bandita 1.5 Trojan Virus contained in the file UPX.EXE which is said was located in my TDS3 install (on both drives).

Helios 4.1.0.1e Trojan Virus located at: windows/system32/Bmp2jpeg.dll

I removed them and rebooted and am trying to figure out if there's an over-arching program that has installed and controlled all of this. Have you heard of any root kits containing these trojans?

thanks
Reply With Quote
  #17  
Old 01-09-2005, 10:48 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Can't say I have ever heard of such a thing before..Where did you get TDS3 from ?
Reply With Quote
  #18  
Old 01-10-2005, 11:13 AM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
I downloaded tds from the link in your posting:
http://tds.diamondcs.com.au/index.php?page=download

but I had installed it prior to when I think the infection took place. I'm thinking something co-opted TDS at that point. Also at 1:00 a.m. today I removed the entire ADO folder containing the MSADO15.dll that kept stalling out my other scanners(did this in safe mode). After this AdAware found several instances of Alexa and Spyware Doctor said it found CWS (although CSShredder has always come up negative).
Reply With Quote
  #19  
Old 01-10-2005, 01:00 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Did it give a location for the cws infection or was it a left over reg key. Also did you run any other scanners ?
Reply With Quote
Reply

  • Submit Thread to Digg Digg
  • Submit Thread to del.icio.us del.icio.us
  • Submit Thread to StumbleUpon StumbleUpon
  • Submit Thread to Google Google
  • Bookmarks

    Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
     
    Thread Tools
    Display Modes

    Posting Rules
    You may not post new threads
    You may not post replies
    You may not post attachments
    You may not edit your posts

    BB code is On
    Smilies are On
    [IMG] code is On
    HTML code is Off
    Forum Jump

    Similar Threads
    Thread Thread Starter Forum Replies Last Post
    Interesting Problem I Have southernlady News & Announcements 3 08-18-2005 04:53 PM
    Interesting Site Stats Mobo News & Announcements 2 07-12-2005 08:07 PM
    Mm I'm Sorry! Bad Virus. savedtheday89 Spyware / Virus Removal 3 06-29-2005 05:19 PM



    All times are GMT -5. The time now is 04:52 PM.


    Firefox 2