Cyberanswers is now on youtube

Register a free account
ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Internet > Spyware / Virus Removal
The Software Store

Spyware / Virus Removal Spyware, virus, browser hijack and other malware removal.

Reply
 
Thread Tools Display Modes
  #11  
Old 01-08-2005, 04:42 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
One more thing. Ctor.dll is related to hotbar adware so click here with internet exolorer and run the scan as it detects that file..[Only Registered and Activated Users Can See Links. Click Here To Register...]
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
Sponsored Links

  #12  
Old 01-08-2005, 04:55 PM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
Okay then, here are the "Findit" results:

Warning! This utility will find legitimate files in addition to malware.
Do not remove anything unless you are sure you know what you're doing.

------- System Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32

01/08/2005 10:32 AM <DIR> dllcache
01/08/2005 12:21 AM <DIR> Microsoft
0 File(s) 0 bytes
2 Dir(s) 18,280,923,136 bytes free

------- Hidden Files in System32 Directory -------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32

01/08/2005 10:32 AM <DIR> dllcache
01/08/2005 12:20 AM 749 wuaucpl.cpl.manifest
01/08/2005 12:20 AM 749 cdplayer.exe.manifest
01/08/2005 12:20 AM 749 sapi.cpl.manifest
01/08/2005 12:20 AM 749 nwc.cpl.manifest
01/08/2005 12:20 AM 749 ncpa.cpl.manifest
5 File(s) 3,745 bytes
1 Dir(s) 18,280,919,040 bytes free

---------- Files Named "Guard" -------------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32


--------- Temp Files in System32 Directory --------

Volume in drive C has no label.
Volume Serial Number is 0490-4145

Directory of C:\WINDOWS\System32

03/25/2003 05:00 AM 2,577 CONFIG.TMP
1 File(s) 2,577 bytes
0 Dir(s) 18,280,919,040 bytes free

---------------- User Agent ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Internet Settings\User Agent\Post Platform]


------------ Keys Under Notify ------------

REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,33,32,2e,64,6c,6c, 00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,72,79,70,74,6e,65,74,2e,64,6c, 6c,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c, 6c,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,63,6c,67,6e,74,66,79,2e,64,6c, 6c,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,6c,6e,6f,74,69,66,79,2e,64,6c, 6c,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEven t"
"Logoff"="UnregisterTicketExpiredNotificationEvent "
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


---------------- Xfind Results -----------------


-------------- Locate.com Results ---------------


C:\WINDOWS\SYSTEM32\
cdplay~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
ncpacp~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
nwccpl~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
sapicp~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K
wuaucp~1.man Sat Jan 8 2005 12:20:14a A..HR 749 0.73 K

5 items found: 5 files, 0 directories.
Total of file sizes: 3,745 bytes 3.66 K

Reply With Quote
  #13  
Old 01-08-2005, 05:03 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
That logfile as well as the previous are clean as a whistle...Try an independent virus scan from [Only Registered and Activated Users Can See Links. Click Here To Register...] maybe because nothing is showing up except this:
O1 - Hosts: 64.91.255.87 [Only Registered and Activated Users Can See Links. Click Here To Register...]
Then reset the homepage..and reboot.
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
  #14  
Old 01-09-2005, 12:06 AM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
Okay then, after numerous attempts to run various online virus scanners, Adaware, Ewido security suite and Tauscan, they all hang up and die (two of them hung up on MSADO15.dll at 1% of the scan, then hung the whole system up). I'm wondering if you have any advide on detecting and/or removing rootkit type invasions?
Reply With Quote
  #15  
Old 01-09-2005, 12:15 AM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
Try updationg the version of that file by downloading and replacing with this [Only Registered and Activated Users Can See Links. Click Here To Register...]. Be sure however to copy and paste the current file so it can be placed back if need be..
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
  #16  
Old 01-09-2005, 10:45 PM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
Well, when I tried copying the new msado15.dll the whole system froze just upon trying to execute a right click copy command. I rebooted and downloaded and installed Microsoft's new version of what used to be Giant Antispy (or something like that). It reported finding SearchSquire Adware installed with the following keys:
Infected registry keys/values detected
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\ZoneMap\Domains\searchsquire.com
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\ZoneMap\Domains\searchsquire.com * 4

I then rebooted this morning with a BART's pe disk made from a clean machine last Thursday. After running several scanner with nothing reported, I ran a rather complete, almost 8 hour Tauscan from the disk and found the following:

Tequilla Bandita 1.5 Trojan Virus contained in the file UPX.EXE which is said was located in my TDS3 install (on both drives).

Helios 4.1.0.1e Trojan Virus located at: windows/system32/Bmp2jpeg.dll

I removed them and rebooted and am trying to figure out if there's an over-arching program that has installed and controlled all of this. Have you heard of any root kits containing these trojans?

thanks
Reply With Quote
  #17  
Old 01-09-2005, 10:48 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
Can't say I have ever heard of such a thing before..Where did you get TDS3 from ?
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
  #18  
Old 01-10-2005, 11:13 AM
rathnid rathnid is offline
Junior Member
 
Join Date: Jan 2005
Posts: 9
I downloaded tds from the link in your posting:
[Only Registered and Activated Users Can See Links. Click Here To Register...]

but I had installed it prior to when I think the infection took place. I'm thinking something co-opted TDS at that point. Also at 1:00 a.m. today I removed the entire ADO folder containing the MSADO15.dll that kept stalling out my other scanners(did this in safe mode). After this AdAware found several instances of Alexa and Spyware Doctor said it found CWS (although CSShredder has always come up negative).
Reply With Quote
  #19  
Old 01-10-2005, 01:00 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,612
Send a message via MSN to Mobo
Did it give a location for the cws infection or was it a left over reg key. Also did you run any other scanners ?
__________________
[Only Registered and Activated Users Can See Links. Click Here To Register...] [Only Registered and Activated Users Can See Links. Click Here To Register...]

Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Interesting Problem I Have southernlady News & Announcements 3 08-18-2005 04:53 PM
Interesting Site Stats Mobo News & Announcements 2 07-12-2005 08:07 PM
Mm I'm Sorry! Bad Virus. savedtheday89 Spyware / Virus Removal 3 06-29-2005 05:19 PM


All times are GMT -5. The time now is 04:44 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved