fellow folder - big problems - logs included

13»

Comments

  • TroganTrogan London, UK
    edited October 2006
    Does Norton say where its finding the file from? The location of it?

    Have the emails started again?
  • stacy3stacy3 NY
    edited October 2006
    Does Norton say where its finding the file from? The location of it?

    Not that I can see......next time I will scan it when it pops up and find out more.

    Have the emails started again?
    Yes, not every day, but maybe every other day or so, I end up with 10-15 in a row all from that same group of people - all with attachments.

    I also got a note from one of those people the other day saying that she is getting multiple emails from former classmates all sent to her bulk folder with viruses. I just thought it was my computer sending them because I was the coordinator for the class reunion and had all those email addresses separated into their own "list". But maybe it's not?

    (when in the world do you sleep?) :smiles:

    Stacy
  • stacy3stacy3 NY
    edited October 2006
    sorry, part of my reply is inside the quote.
  • TroganTrogan London, UK
    edited October 2006
    I sleep when I can! :D

    Download AIMFix from here and save it to your Desktop >> http://www.jayloden.com/software.htm
    Run the tool, and when it has finished, it will produce a log on your Desktop. Please post it here.

    Also, please RIGHT-CLICK HERE and Save As (in IE it's "Save Target As") to download Silent Runners.
    • Save it to the desktop.
    • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
    • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
    • Once you receive the prompt "All Done!", double-click the new text file on the desktop, copy that entire log, and paste it here.
    *NOTE* If you receive any warning message about scripts, please choose to allow the script to run.
  • stacy3stacy3 NY
    edited October 2006
    Here is the Aimfix log:

    AIMFix version: 1.6.1012.1020 (Oct 12 2006 10:20:15)
    SeDebug Privilege set successfully

    ***ANY VIRUS FILES REMOVED WILL BE LISTED BELOW***

    BlockRemove(): Now checking for Block-Checker: .5
    BlockRemove(): Block-Checker not found
    IMNamesRemove(): Now checking for IMNames: .2
    IMNamesRemove(): IM Names not found
    CleanMstc(): mstc not found

    ***RUN COMPLETED. ANY FILES REMOVED LISTED ABOVE***
  • stacy3stacy3 NY
    edited October 2006
    OK, all set - here is the silent runner log:

    "Silent Runners.vbs", revision 49, http://www.silentrunners.org/
    Operating System: Windows XP SP2
    Output limited to non-default values, except where indicated by "{++}"


    Startup items buried in registry:

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "MSMSGS" = ""C:\Program Files\Messenger\msmsgs.exe" /background" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    "HPDJ Taskbar Utility" = "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe" ["HP"]
    "HPHUPD05" = "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" ["Hewlett-Packard"]
    "ccApp" = ""C:\Program Files\Common Files\Symantec Shared\ccApp.exe"" ["Symantec Corporation"]
    "URLLSTCK.exe" = ""C:\Program Files\Norton Internet Security\UrlLstCk.exe"" ["Symantec Corporation"]
    "SunJavaUpdateSched" = ""C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"" ["Sun Microsystems, Inc."]
    "!AVG Anti-Spyware" = ""C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized" ["Anti-Malware Development a.s."]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    {02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Yahoo! Companion BHO"
    \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll" ["Yahoo! Inc."]
    {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "AcroIEHlprObj Class"
    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
    {53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]
    {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "SSVHelper Class"
    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll" ["Sun Microsystems, Inc."]
    {9ECB9560-04F9-4bbc-943D-298DDF1699E1}\(Default) = "Norton Internet Security 2006"
    -> {HKLM...CLSID} = "CNisExtBho Class"
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]
    {A8F38D8D-E480-4D52-B7A2-731BB6995FDD}\(Default) = "NAV Helper"
    -> {HKLM...CLSID} = "CNavExtBho Class"
    \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]
    {FDD3B846-8D59-4ffb-8758-209B6AD74ACC}\(Default) = (no title provided)
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyviewer.dll" [MS]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
    "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
    -> {HKLM...CLSID} = "Display Panning CPL Extension"
    \InProcServer32\(Default) = "deskpan.dll" [file not found]
    "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
    -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
    "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
    -> {HKLM...CLSID} = "Outlook File Icon Extension"
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\OLKFSTUB.DLL" [MS]
    "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
    -> {HKLM...CLSID} = (no title provided)
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
    "{5E44E225-A408-11CF-B581-008029601108}" = "Adaptec DirectCD Shell Extension"
    -> {HKLM...CLSID} = "Adaptec DirectCD Shell Extension"
    \InProcServer32\(Default) = "C:\PROGRA~1\Roxio\EASYCD~1\DirectCD\Shellex.dll" ["Roxio"]
    "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
    -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
    \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ["RealNetworks, Inc."]
    "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}" = "iTunes"
    -> {HKLM...CLSID} = "iTunes"
    \InProcServer32\(Default) = "C:\Program Files\iTunes\iTunesMiniPlayer.dll" ["Apple Computer, Inc."]

    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
    <<!>> "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}" = "AVG Anti-Spyware 7.5"
    -> {HKLM...CLSID} = "CShellExecuteHookImpl Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" ["Anti-Malware Development a.s."]

    HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
    {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
    -> {HKLM...CLSID} = "PDF Shell Extension"
    \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

    HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
    AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
    -> {HKLM...CLSID} = "CContextScan Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]
    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
    -> {HKLM...CLSID} = "IEContextMenu Class"
    \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]

    HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
    AVG Anti-Spyware\(Default) = "{8934FCEF-F5B8-468f-951F-78A921CD3920}"
    -> {HKLM...CLSID} = "CContextScan Object"
    \InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll" ["Anti-Malware Development a.s."]

    HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
    Symantec.Norton.Antivirus.IEContextMenu\(Default) = "{FAD61B3D-699D-49B2-BE16-7F82CB4C59CA}"
    -> {HKLM...CLSID} = "IEContextMenu Class"
    \InProcServer32\(Default) = "C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll" ["Symantec Corporation"]


    Group Policies {policy setting}:

    Note: detected settings may not have any effect.

    HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "DisableRegistryTools" = (REG_DWORD) hex:0x00000000
    {Prevent access to registry editing tools}

    "DisableTaskMgr" = (REG_DWORD) hex:0x00000000
    {Remove Task Manager}

    "DisableRegedit" = (REG_DWORD) hex:0x00000000
    {unrecognized setting}

    HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

    "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Shutdown: Allow system to be shut down without having to log on}

    "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
    {Devices: Allow undock without having to log on}


    Active Desktop and Wallpaper:

    Active Desktop may be disabled at this entry:
    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

    Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
    HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"

    Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    HKCU\Control Panel\Desktop\
    "Wallpaper" = "C:\Documents and Settings\Stacy\Local Settings\Application Data\Microsoft\Wallpaper1.bmp"


    Enabled Screen Saver:

    HKCU\Control Panel\Desktop\
    "SCRNSAVE.EXE" = "C:\WINDOWS\System32\sstext3d.scr" [MS]


    Startup items in "Stacy" & "All Users" startup folders:

    C:\Documents and Settings\Stacy\Start Menu\Programs\Startup
    "Folding@Home 5.03" -> shortcut to: "C:\Program Files\Folding@Home\winFAH.exe" ["Stanford University"]


    Enabled Scheduled Tasks:

    "Disk Cleanup" -> launches: "C:\WINDOWS\SYSTEM32\cleanmgr.exe" [MS]
    "HP DArC Task #Hewlett-Packard#7200#CN3862C21CI5" -> launches: "C:\Program Files\HP\hpcoretech\comp\hpdarc.exe /#Hewlett-Packard#7200#CN3862C21CI5" ["Hewlett-Packard Company"]
    "HP Usg Daily" -> launches: "C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe" [empty string]
    "Norton AntiVirus - Run Full System Scan - Stacy" -> launches: "C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe /TASK:"C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Tasks\mycomp.sca"" ["Symantec Corporation"]


    Winsock2 Service Provider DLLs:

    Namespace Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
    000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

    Transport Service Providers

    HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
    %SystemRoot%\system32\mswsock.dll [MS], 01 - 03, 06 - 19
    %SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


    Toolbars, Explorer Bars, Extensions:

    Toolbars

    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
    "{EF99BD32-C1FB-11D2-892F-0090271D4F88}"
    -> {HKLM...CLSID} = "Yahoo! Companion"
    \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll" ["Yahoo! Inc."]
    "{0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7}"
    -> {HKLM...CLSID} = "Norton Internet Security 2006"
    \InProcServer32\(Default) = "C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll" ["Symantec Corporation"]

    Explorer Bars

    HKCU\Software\Microsoft\Internet Explorer\Explorer Bars\
    {9404901D-06DA-4B23-A0EE-3EA4F64EC9B3}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "MoneySide"
    \InProcServer32\(Default) = "C:\Program Files\Microsoft Money\System\mnyviewer.dll" [MS]
    {FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Real.com"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]

    HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\
    {FE54FA40-D68C-11D2-98FA-00C0F0318AFE}\(Default) = (no title provided)
    -> {HKLM...CLSID} = "Real.com"
    \InProcServer32\(Default) = "C:\WINDOWS\System32\Shdocvw.dll" [MS]

    Extensions (Tools menu items, main toolbar menu buttons)

    HKLM\Software\Microsoft\Internet Explorer\Extensions\
    {08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
    "MenuText" = "Sun Java Console"
    "CLSIDExtension" = "{CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}"
    -> {HKCU...CLSID} = "Java Plug-in 1.5.0_09"
    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll" ["Sun Microsystems, Inc."]
    -> {HKLM...CLSID} = "Java Plug-in 1.5.0_09"
    \InProcServer32\(Default) = "C:\Program Files\Java\jre1.5.0_09\bin\npjpi150_09.dll" ["Sun Microsystems, Inc."]


    HOSTS file

    C:\WINDOWS\System32\drivers\etc\HOSTS

    maps: 44 domain names to IP addresses,
    41 of the IP addresses are *not* localhost!


    Running Services (Display Name, Service Name, Path {Service DLL}):

    Automatic LiveUpdate Scheduler, Automatic LiveUpdate Scheduler, ""C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"" ["Symantec Corporation"]
    AVG Anti-Spyware Guard, AVG Anti-Spyware Guard, "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe" ["Anti-Malware Development a.s."]
    iPodService, iPodService, "C:\Program Files\iPod\bin\iPodService.exe" ["Apple Computer, Inc."]
    Norton AntiVirus Auto-Protect Service, navapsvc, ""C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe"" ["Symantec Corporation"]
    Norton Protection Center Service, NSCService, ""C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE"" ["Symantec Corporation"]
    Symantec Core LC, Symantec Core LC, ""C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe"" ["Symantec Corporation"]
    Symantec Event Manager, ccEvtMgr, ""C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"" ["Symantec Corporation"]
    Symantec Network Drivers Service, SNDSrvc, ""C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe"" ["Symantec Corporation"]
    Symantec Network Proxy, ccProxy, ""C:\Program Files\Common Files\Symantec Shared\ccProxy.exe"" ["Symantec Corporation"]
    Symantec Settings Manager, ccSetMgr, ""C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"" ["Symantec Corporation"]
    Symantec SPBBCSvc, SPBBCSvc, ""C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"" ["Symantec Corporation"]


    Print Monitors:

    HKLM\System\CurrentControlSet\Control\Print\Monitors\
    EPSON V4 Monitor3SA\Driver = "EBPMON3.DLL" ["SEIKO EPSON CORPORATION"]
    hpzlnt09\Driver = "hpzlnt09.dll" ["HP"]


    <<!>>: Suspicious data at a malware launch point.

    + This report excludes default entries except where indicated.
    + To see *everywhere* the script checks and *everything* it finds,
    launch it from a command prompt or a shortcut with the -all parameter.
    + To search all directories of local fixed drives for DESKTOP.INI
    DLL launch points, use the -supp parameter or answer "No" at the
    first message box and "Yes" at the second message box.
    (total run time: 109 seconds, including 18 seconds for message boxes)
  • TroganTrogan London, UK
    edited October 2006
    That log is clean.

    I seriously don't know whats causing the emails. :(
  • stacy3stacy3 NY
    edited October 2006
    OK - thanks for checking, though, Trogan.

    Stacy
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited October 2006
    Does yahoo email allow you to view the email headers? (The part of the message that shows the various servers the message has passed through on its way to you.) If so, copy & paste one of them here, or post a screenshot of it.
  • stacy3stacy3 NY
    edited October 2006
    OK - prof - didn't know you could do that...:rolleyes2

    but I looked around a bit and here is the latest one I got: (sorry, I don't know how to do a screen shot...)

    From [email]mic[/email] Thu Oct 12 12:52:28 2006
    X-Apparently-To: [email]stacy3[/email] via 209.191.68.171; Thu, 12 Oct 2006 12:52:36 -0700
    X-YahooFilteredBulk: 24.49.70.43
    X-Originating-IP: [24.49.70.43]
    Return-Path: {mic}
    Authentication-Results: mta247.mail.re4.yahoo.com from=yahoo.com; domainkeys=neutral (no sig)
    Received: from 24.49.70.43 (EHLO yahoo.com) (24.49.70.43) by mta247.mail.re4.yahoo.com with SMTP; Thu, 12 Oct 2006 12:52:36 -0700
    From: Send an Instant Message [email]mic[/email] View Contact Details View Contact Details Add Mobile Alert
    To: [email]stacy[/email]
    Subject: Request
    Date: Thu, 12 Oct 2006 15:52:28 -0400
    MIME-Version: 1.0
    Content-Type: multipart/mixed; boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
    X-Priority: 3
    X-MSMail-Priority: Normal
    Content-Length: 18019


    For more information see the attached document.



    Attachments
    Attachment scanning provided by:

    Files:
    textfile5.pif textfile5.pif (18k) Scan and Save to Computer - Save to Yahoo! Briefcase
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited October 2006
    I edited out the actual email addresses so the spambots couldn't get you. :wave:

    I can't find much to go on there. :-/ Maybe someone else can spot something. Have you contacted the person who is mentioned as the sender? They may benefit from a visit here as well. :)
  • stacy3stacy3 NY
    edited October 2006
    oh thanks for the edit, prof.

    There are actually multiple senders (you probably don't want 20 of my former classmates coming and asking questions :bigggrin:) - all from one "list" in my address book...I have more - would seeing any more help?

    Do you know what this is? I don't.

    mta247.mail.re4.yahoo.com
  • TroganTrogan London, UK
    edited October 2006
    Well...I don't mind looking at the logs, even if it is 20. :o

    If no one wants to post their HJT logs, then ask them to run the FixNetsky tool you ran before.

    Your computer is clean and I'm very sure of that. One of your contacts are likely infected.
  • stacy3stacy3 NY
    edited October 2006
    OK, thanks Trogan. I will try to contact them and encourage them to resolve it, one way or another.

    Oh, and you had asked about the location of that risk that Norton kept detecting. The location was this.

    C:/Recyclers\S-1-521-3341562259-1085806099-568186159-1006\Dc1.exe

    The Risk name was Adware.Lop and I had Norton remove it...It said it's resolved. It's probably quarantined. Should I go in and delete the quarantined files?

    Thanks!!!!
  • TroganTrogan London, UK
    edited October 2006
    Norton quarantined it? :eek: It did something good then. :tongue2:

    Lop as an infection is generally harmless; just causes a lot of adverts. If its in quarantine, then you can leave it there. It will not cause any harm. :)
  • stacy3stacy3 NY
    edited October 2006
    yeah I had the same reaction...:bigggrin:
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited October 2006
    stacy3 wrote:
    ...you had asked about the location of that risk that Norton kept detecting. The location was this.

    C:/Recyclers\S-1-521-3341562259-1085806099-568186159-1006\Dc1.exe...
    That means it was in the Recycle Bin. It's not a bad idea to empty that after cleaning out anything rotten, anyway. :)
  • stacy3stacy3 NY
    edited October 2006
    ah, thanks, prof - I'll do that.

    "Your computer is clean and I'm very sure of that. "
    :celebrate

    THANKS!!!!!!!!!!!!!!!!!
Sign In or Register to comment.