services.exe app error 0x37001160 - win xp wont boot all the way

Hello, I have done some research on this problem, but I am afraid of being dnagerous, so I think I need some experienced guidance.

running win xp SP2 - all updates.

I was in the process of installing BitDefender v10 and at the same time I think windows update was doing it's thing with some updates from this week. Anyway, the installation of both hung up. After 10 mins of no activity, I rebooted. Now, I get the following error msg when my computer starts up:

Services.exe application error. The instruction at "0x37001160" referenced memory at "0x37001160". The memory could not be "read". Click OK to terminate the program, click cancel to debug the program.

OK gives a couple more similar error messages, except they are for lsass.exe and explorer.exe.

Then finally, I get the NT Authority error that says its shutting down in 60 seconds. due to \windows\system32\services.exe, status code 1073741819. It automatically restarts and goes through the same thing.

I can start in safe mode and safe mode with networking. So it looks like I screwed up my laptop. :-/

I've read several sites that seem to think it has to do with a worm, but I think the symptoms are not quite the same. In any event, I scanned for viruses with upto-date defs and online scanners and found none. no lsass virus either.

All this because I was installing that dang BitDefender to help a friend create a rescue CD!! Arghhh. Bottom line, what do I need to do and where do I begin to fix this problem?? I have little computer experience to fix this sort of thing. PLEASE HELP!!

Thank you,
maxwelltf
«13

Comments

  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited January 2007
    We had another member with the same error message.

    Post a HijackThis log. If we spot anything rotten we'll go from there. If not, we'll check out other possibilities. :)
  • edited January 2007
    Hi thanks. Yes, I read tiger's thread, but there are some differences. Namely, my system restore was turned off. I am almost in disbelief as to how that can be, but it is true. It is turned off. So, I figured I should start a fresh thread on the the subject. HJT log is attached. Hope this helps.... Thanks for your help so much! PS - I grew up in Brookpark and family lives around the westside. -Tom
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited January 2007
    You can go ahead and post the HJT log here if you want. If I see anything suspicious I'll send this thread over to our crack SVT Swat Team for cleanup. :)
  • edited January 2007
    Cool. I attached the log in the last post - did it not show up? If not, here it is inline...

    Logfile of HijackThis v1.99.1
    Scan saved at 4:50:21 PM, on 1/11/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
    C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
    C:\Program Files\HJT\Analyse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156438812346
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (file missing)
    O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

    ===================end
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited January 2007
    Try clicking Start>>Run, type in msconfig, then click OK. Go to the startup tab and uncheck any non-essential programs you see. After that, see if you can boot normally.

    I'd include anything having to do with BitDefender, since it looks like the messed up installation may be the source of your problem:
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

    I'd also disable any Services related to BitDefender for the time being.

    If that gets you back in business, try uninstalling BitDefender completely, reboot, then give it another shot. I'm sure this has occurred to you by now, but you're playing with fire to try and update two things at the same time - especially if one of them is a MS Hotfix via Windows Update. :eek3:
  • edited January 2007
    OK done. Unchecked all unessentials, including any items with BD in the name. Unable to boot normal. :-(

    Did you notice that there are several files "missing" in the log? They mostly look like windows system files. seems to line up with the services, lsass, and explorer app errors, no?

    10-4 on the double install wasnt intentional - forgot it was running in the background. argghhhh!!!
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited January 2007
    It appears that this one may be up to no good. (Ignore the advice to buy their program - our guys will get you fixed up at no charge.)

    I'm going to turn this over to our experts in the field to see what they advise. If the problem persists after they've given you a clean bill of health I'll have them send it back here for more noodling. :thumbsup:
  • edited January 2007
    Ok thanks. I'll wait to hear from them. Thought that Prevx software was pretty solid. Hmmm.
  • jmoney3457jmoney3457 Maine
    edited January 2007
    prof is right, it appears that particular file is added by a worm..see here for more info..lets begin cleaning you up:wink: please do this..Download ATF Cleaner
    • Double-click ATF-Cleaner.exe to run the program.
    • Click Select All found at the bottom of the list.
    • Click the Empty Selected button.
    If you use Firefox browser, do this also:
    • Click Firefox at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser, do this also:
    • Click Opera at the top and choose Select All from the list.
    • Click the Empty Selected button.
    • NOTE : If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.

    then, First download AVG anti-spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    1. Once you have downloaded AVG anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need run AVG and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close AVG anti-spyware, Do Not run a scan just yet, we will shortly.
    1. Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
      IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process
    2. Lauch AVG-anti-spyware by double-clicking the icon on your desktop.
    3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    4. AVG will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    5. If you have any infections you will prompted, then select "Apply all actions"
    6. Next select the "Reports" icon at the top.
    7. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    8. Close AVG and reboot your system back into Normal Mode and post the results of the AVG report scan.
  • edited January 2007
    Ok - I'll do the steps. It will take me this evening to do so.

    In the meantime, however, isnt Bit Defender a legit app or not? What about Prevx?

    Finally, is there any concern about the system files listed as "missing" in the HJT log? Does it not appear there is something wrong there - perhaps from the install gone wrong?
  • profdlpprofdlp The Holy City Of Westlake, Ohio
    edited January 2007
    maxwelltf wrote:
    ...Finally, is there any concern about the system files listed as "missing" in the HJT log? Does it not appear there is something wrong there - perhaps from the install gone wrong?
    I'll defer to the experts on this one (and you couldn't ask for better help than what you'll get from jmoney), but I know that at least one of those (msgrapp.dll) is commonly missing from a lot of HJT logs I've seen.

    Bitdefender is a fine program, but trying to install it on an already infected machine is likely what caused the problem to begin with. (Not that you had any way of knowing that.) It's like your doctor telling you not to take the flu shot if you think you may already have the flu. :D

    As for Prevx, I have nothing against it, but I'm always a little wary of programs which find a problem and then tell you to cough up some dough to get it fixed. ADDED: I'm also wary of programs which send out shills to pimp their product. Isn't it good enough to stand on its own? Most of the trustworthy AntiVirus programs (like BitDefender) allow you to do an online scan and actually fix your problems before they start asking for your money. :wave:
  • edited January 2007
    Thanks JMoney - all steps completed. Here is the AVG log. I have not tried to reboot into normal mode yet. Will await your next steps.
    Thanks - maxwelltf.

    AVG Anti-Spyware - Scan Report

    + Created at: 11:44:16 PM 1/11/2007

    + Scan result:

    C:\Documents and Settings\Administrator\Desktop\066dbba1b07d9fe3110ba60066448d386.zip/McAfee VirusScan Enterprise - v.8.0i.exe -> Trojan.Small : Cleaned with backup (quarantined).


    ::Report end
  • edited January 2007
    profdlp wrote:
    As for Prevx, I have nothing against it, but I'm always a little wary of programs which find a problem and then tell you to cough up some dough to get it fixed. ADDED: I'm also wary of programs which send out shills to pimp their product. Isn't it good enough to stand on its own? Most of the trustworthy AntiVirus programs (like BitDefender) allow you to do an online scan and actually fix your problems before they start asking for your money. :wave:
    Hi Prof,

    Just thought I'd shill your forum, as I have done to so many others.

    Whintersby
  • jmoney3457jmoney3457 Maine
    edited January 2007
    profdlp wrote:
    (and you couldn't ask for better help than what you'll get from jmoney)
    thanks prof:)
    maxwelltf wrote:
    In the meantime, however, isnt Bit Defender a legit app or not? What about Prevx?

    Finally, is there any concern about the system files listed as "missing" in the HJT log? Does it not appear there is something wrong there - perhaps from the install gone wrong?
    yes bitdefender is a HIGHLY regarded anti virus program ranking high among AV programs, prevx is legit also..though I have no personal experience with it and have heard mostly good things about it...yes the *missing files* is a bug in the current version of HJT, it's only true for 02-3 entries:)...lastly please post new HJT Log max:)
  • edited January 2007
    Thanks Jmoney - OK - here's a new HJT log. Have done all this from safe mode. havent try to boot to nrormal mode since doing AVG scan. will await next steps. -max

    Logfile of HijackThis v1.99.1
    Scan saved at 8:38:50 AM, on 1/12/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
    C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HJT\Analyse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156438812346
    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab
    O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
    O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
    O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
    O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
    O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (file missing)
    O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\WINDOWS\system32\msasvc.exe (file missing)
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
    O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
    O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
  • TroganTrogan London, UK
    edited January 2007
    Sorry to jump in the thread like this. However, I don't have good knows.

    The file identified by Prof belongs to the IRCBot Trojan, which has Backdoor functionality. This gives intruders complete control of your computer, logging key strokes, stealing information, etc. :(

    You are strongly advised to do the following immediately!:
    • Disconnect infected computer from the internet and from any networked computers until the computer can be cleaned.
    • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
    • From a clean computer, change *all* of your online passwords -- for ISP login, email, banks, financial accounts, PayPal, eBay, online companies, and any online forums or groups you belong to.
        Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
      Because of its backdoor functionality, your PC is very likely compromised and there is no way to be sure it can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. However, if you do not have the resources to reinstall your OS and would like me to attempt to clean your machine, I will be happy to do so.

      To help you make a more informed decision, please read the following articles: Should you have any questions, please feel free to ask

      Please let me know your decision and we'll get started with clean up if that's what you choose.
    • edited January 2007
      Hello Trogan - well now that some of the blood has returned to my head - I have a couple questions: How can you tell it is infected with IRCBot? This is my primary Laptop and has all my personal files, but I do not use it for banking except Paypal and Hotmail and will change those passwords now from this clean PC. (However this PC has been on the network with the Laptop - so how can we tell if it is inected as well?)

      I truly expected these current set of problems to be from a simultaneous program installation and "windows XP update", both of which hung and were uncleanly stopped with a reboot.

      My decision to clean/correct the laptop and not reformat the hard drive. I can attempt an OS reinstall, but I must find the Win XP Pro CD and not 100% sure I can find it.

      max
    • TroganTrogan London, UK
      edited January 2007
      Hi Max
      Hello Trogan - well now that some of the blood has returned to my head - I have a couple questions: How can you tell it is infected with IRCBot? This is my primary Laptop and has all my personal files, but I do not use it for banking except Paypal and Hotmail and will change those passwords now from this clean PC. (However this PC has been on the network with the Laptop - so how can we tell if it is inected as well?)
      Looking at the link Prof posted (http://fileinfo.prevx.com/adware/qqc6f641158518-MSAS22915957/MSASVC.EXE.html) shows its an IRCBot and some other research shows this. If you post a HijackThis log from the PC after we have finished with the Laptop, I'll take a look at it.
      I truly expected these current set of problems to be from a simultaneous program installation and "windows XP update", both of which hung and were uncleanly stopped with a reboot.
      Could have been, but not sure. It may be that the Bot knew something was being installed and decided to cause damage? I don't know. Bots can do damage if not caught and removed early.
      My decision to clean/correct the laptop and not reformat the hard drive. I can attempt an OS reinstall, but I must find the Win XP Pro CD and not 100% sure I can find it.
      Lets try and do a clean up.

      Please do the following...

      1. Download SDFix and save it to your Desktop.

      Double click SDFix.exe and it will extract the files to %systemdrive%
      (Drive that contains the Windows Directory, typically C:\SDFix)

      Please then reboot your computer in Safe Mode by doing the following :
      • Restart your computer
      • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
      • Instead of Windows loading as normal, the Advanced Options Menu should appear;
      • Select the first option, to run Windows in Safe Mode, then press Enter.
      • Choose your usual account.
      • Open the extracted SDFix folder and double click RunThis.bat to start the script.
      • Type Y to begin the cleanup process.
      • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
      • Press any Key and it will restart the PC.
      • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
      • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
        (Report.txt will also be copied to Clipboard ready for posting back on the forum).
      • Finally paste the contents of the Report.txt, along with a new HijackThis log in your next post.
      2. I need to see another log from HijackThis.
      • Run Hijackthis.
      • Click on Open the Misc Tools section.
      • Next click on Open uninstall manager.
      • Press the Save list button.
      • Save the file to your desktop, with the default name of uninstall_list
      • Copy & Paste the entire contents of that file in your in your next post.
      3. Please post the following...

      1) SDFix Report.txt
      2) Uninstall list
      3) New HijackThis log
    • edited January 2007
      OK - I will do the steps and report back. (BTW - I can only boot into safe mode - normal mode hangs with the services.exe error.) I truly appreciate your help with this. Being the way I am, I do want to ask you about the msasvc.exe file: Doesn't the HJT log say that the msasvc.exe file is missing? I searched the laptop HD for msasvc.exe and it does not appear to be on the HD (hidden files shown). Is it possible that the *authentic* Microsoft msasvc.exe file that belongs in WINDOWS\SYSTEM32\ was corrupted or incompletely loaded during the interrupted windows XP update and, since it is missing, is part of the laptop's bootup problem?

      This laptop has always been behind a firewall and is always up to date with Windows Update. I am pretty religious about it.

      Will proceed with your steps and will anxiously await your thoughts. -max
    • TroganTrogan London, UK
      edited January 2007
      OK - I will do the steps and report back. (BTW - I can only boot into safe mode - normal mode hangs with the services.exe error.) I truly appreciate your help with this. Being the way I am, I do want to ask you about the msasvc.exe file: Doesn't the HJT log say that the msasvc.exe file is missing? I searched the laptop HD for msasvc.exe and it does not appear to be on the HD (hidden files shown). Is it possible that the *authentic* Microsoft msasvc.exe file that belongs in WINDOWS\SYSTEM32\ was corrupted or incompletely loaded during the interrupted windows XP update and, since it is missing, is part of the laptop's bootup problem?
      You should be able to boot into Normal Mode once the Bot has been removed. When HijackThis reports "File Missing" it doesn't generally mean its missing - its a known bug in the program. It's only true for O2 and O3 entries as Jmoney mentioned above. Also, I don't think there is a legit registered Microsoft msasvc.exe file. Why you could not find it after searching, I don't know.
      This laptop has always been behind a firewall and is always up to date with Windows Update. I am pretty religious about it.
      Thats good, but how long was the computer without an Anti-Virus before you tried to install BitDefender? Could be the reason why the Bot got in.
    • jmoney3457jmoney3457 Maine
      edited January 2007
      trogan to the rescue once again:celebrate
    • edited January 2007
      Hello Trogan - ok at the end of this post are the three log files as instructed.
      Here is some additional information:
      Once the SDFix scan is complete and the PC automatically reboots, it does so into normal mode, and the red X error message still occurs. Thus f there is some scanning that SDFIx tries to do upon reboot, I doubt it can do so, since booting into normal mode results in the red X errors. The exact error messages are as follows: <<Services.exe application error. The instruction at "0x37001160" referenced memory at "0x37001160". The memory could not be "read".>> At this point, the PC has only booted to the desktop wallpaper, but no icons on the desktop nor taskbar/clock at the bottom. Clicking OK on the red X error message yields the same error message again. Click OK again gives the same error message but for "Explorer.exe", twice, which is then followed by the same error message for "lsass.exe". When these red X errors are done, the "NT Authority\System" begins the 1 minute shutdown. The PC never makes it to the desktop, no desktop icons appear, no tool bar. The PC then in fact does not reboot - it just hangs there. (FYI - I can do a ctrl-alt-del while it is hanging there and after about 3-4 mins the task manager appears, if that means anything. ) Will await your next thoughts/steps. -max

      ===============================
      SDFix: Version 1.58

      Fri 01/12/2007 - 13:28:30.29

      Microsoft Windows XP [Version 5.1.2600]

      Running From: C:\SDFix

      Safe Mode:

      Checking Services:

      Name:

      MsaSvc

      Path:

      C:\WINDOWS\system32\msasvc.exe

      MsaSvc Deleted

      Restoring Windows Registry Entries
      Restoring Default Hosts File
      ===============================

      Uninstall_lst.txt log

      Adobe Flash Player 9 ActiveX
      Adobe Reader 7.0.8
      AirXpert Tri-Mode Dualband Adapter
      Apple Software Update
      ATI - Software Uninstall Utility
      ATI Control Panel
      ATI Display Driver
      AVG Anti-Spyware 7.5
      BitDefender Antivirus Plus v10
      BlackBerry Desktop Software 4.2
      BlackBerry Desktop Software 4.2
      CCleaner (remove only)
      Data Lifeguard Tools
      DivX Codec
      Easy CD & DVD Creator 6
      Garmin Training Center
      Garmin WebUpdater
      Google Earth
      Google Video Player
      HDInfo - Freeware Version
      HijackThis 1.99.1
      Hotfix for Windows XP (KB926239)
      Hotfix for Windows XP (KB928388)
      HP Photo and Imaging 2.0 - All-in-One
      HP Photo and Imaging 2.0 - All-in-One Drivers
      HP Photo and Imaging 2.0 - hp psc 2200 series
      hp psc 2200 series
      Image Resizer Powertoy for Windows XP
      iTunes
      J2SE Runtime Environment 5.0 Update 9
      Java(TM) SE Runtime Environment 6
      LiveUpdate 2.6 (Symantec Corporation)
      McAfee VirusScan Enterprise
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Hotfix (KB886903)
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft MapPoint 2002 North America
      Microsoft Office OneNote 2003
      Microsoft Office Professional Edition 2003
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Visio Standard 2002 [English]
      Mozilla Firefox (1.5.0.9)
      MSN Messenger 7.5
      MSXML 4.0 SP2 (KB925672)
      MSXML 4.0 SP2 (KB927978)
      OverDrive Media Console
      Panda ActiveScan
      PCTEL 2304WT V.9x MDC Modem Drivers
      Photo Story 3 for Windows
      PowerDVD 5.1
      Prevx1
      QuickTime
      RealPlayer
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player 6.4 (KB925398)
      Security Update for Windows Media Player 9 (KB917734)
      Security Update for Windows XP (KB890046)
      Security Update for Windows XP (KB893756)
      Security Update for Windows XP (KB896358)
      Security Update for Windows XP (KB896423)
      Security Update for Windows XP (KB896424)
      Security Update for Windows XP (KB896428)
      Security Update for Windows XP (KB899587)
      Security Update for Windows XP (KB899589)
      Security Update for Windows XP (KB899591)
      Security Update for Windows XP (KB900725)
      Security Update for Windows XP (KB901017)
      Security Update for Windows XP (KB901214)
      Security Update for Windows XP (KB902400)
      Security Update for Windows XP (KB904706)
      Security Update for Windows XP (KB905414)
      Security Update for Windows XP (KB905749)
      Security Update for Windows XP (KB908519)
      Security Update for Windows XP (KB911562)
      Security Update for Windows XP (KB911567)
      Security Update for Windows XP (KB911927)
      Security Update for Windows XP (KB912919)
      Security Update for Windows XP (KB913433)
      Security Update for Windows XP (KB913580)
      Security Update for Windows XP (KB914388)
      Security Update for Windows XP (KB914389)
      Security Update for Windows XP (KB916281)
      Security Update for Windows XP (KB917159)
      Security Update for Windows XP (KB917344)
      Security Update for Windows XP (KB917422)
      Security Update for Windows XP (KB917953)
      Security Update for Windows XP (KB918439)
      Security Update for Windows XP (KB918899)
      Security Update for Windows XP (KB919007)
      Security Update for Windows XP (KB920213)
      Security Update for Windows XP (KB920214)
      Security Update for Windows XP (KB920670)
      Security Update for Windows XP (KB920683)
      Security Update for Windows XP (KB920685)
      Security Update for Windows XP (KB921398)
      Security Update for Windows XP (KB921883)
      Security Update for Windows XP (KB922616)
      Security Update for Windows XP (KB922760)
      Security Update for Windows XP (KB922819)
      Security Update for Windows XP (KB923191)
      Security Update for Windows XP (KB923414)
      Security Update for Windows XP (KB923694)
      Security Update for Windows XP (KB923980)
      Security Update for Windows XP (KB924191)
      Security Update for Windows XP (KB924270)
      Security Update for Windows XP (KB924496)
      Security Update for Windows XP (KB925454)
      Security Update for Windows XP (KB925486)
      Security Update for Windows XP (KB926255)
      Skype 2.5
      Spybot - Search & Destroy 1.4
      Sunbelt CounterSpy
      Symantec Technical Support Web Controls
      Synaptics Pointing Device Driver
      Tweak UI
      Update for Windows XP (KB894391)
      Update for Windows XP (KB898461)
      Update for Windows XP (KB900485)
      Update for Windows XP (KB904942)
      Update for Windows XP (KB908531)
      Update for Windows XP (KB910437)
      Update for Windows XP (KB911280)
      Update for Windows XP (KB916595)
      Update for Windows XP (KB920872)
      Update for Windows XP (KB922582)
      Windows Installer 3.1 (KB893803)
      Windows Live OneCare safety scanner
      Windows Media Connect
      Windows Media Format 11 runtime
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows Media Player 11
      Windows XP Hotfix - KB873339
      Windows XP Hotfix - KB885835
      Windows XP Hotfix - KB885836
      Windows XP Hotfix - KB885884
      Windows XP Hotfix - KB886185
      Windows XP Hotfix - KB887472
      Windows XP Hotfix - KB888113
      Windows XP Hotfix - KB888302
      Windows XP Hotfix - KB890859
      Windows XP Hotfix - KB891781
      WinRAR archiver
      XviD & MP3 Codec Pack (remove only)
      XviD 1.1 final uninstall

      =========================
      Logfile of HijackThis v1.99.1
      Scan saved at 3:02:32 PM, on 1/12/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunThreatEngine.exe
      C:\Program Files\Sunbelt Software\CounterSpy\Consumer\SunProtectionServer.exe
      C:\Program Files\HJT\Analyse.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156438812346
      O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
      O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab
      O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
      O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
      O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
      O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
      O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (file missing)
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
      O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
      O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)

      ===================================
      end
    • edited January 2007
      Trogan wrote:
      Thats good, but how long was the computer without an Anti-Virus before you tried to install BitDefender? Could be the reason why the Bot got in.

      To the best of my knowledge, the laptop was without antivirus for a few days. Long enough I'm sure. It certainly appears that malware has a part to play in the problem, however my suspicion still lives regarding the failed installation of BitDefender combined with simultaneous Windows XP halted. What are your thoughts on that?
    • TroganTrogan London, UK
      edited January 2007
      What happened may have played a part, however, I'm not a Windows expert by any means. What I can say is that infections such as these can cause a lot of damage, like we are seeing now.

      Lets see if we can get Normal Mode to work. So far things don't look to good.

      Restart the computer once more. If nothing loads in Normal Mode at start-up, then open Task Manager and type in explorer.exe.

      Let me know what happens.
    • edited January 2007
      Manually starting explorer from the task manager results in same error "Explorer.EXE application error..." etc with same memory location numbers, etc.

      Although at least this time, booting into normal gave the taskbar at the bottom of the desktop. Progress?

      I can tell the system is "trying" to get started, but something is wrong and holding it back. Seems like it doesnt want to give up. -max
    • TroganTrogan London, UK
      edited January 2007
      I just realised that you also have McAfee VirusScan Enterprise alongside BitDefender Antivirus Plus v10. Having two anti-virus programs can cause conflicts and other problems. You should uninstall one of them through add/remove programs.

      Might have to do that in Safe Mode.

      Try Normal Mode after removing one of those. Let me know when that is done.
    • edited January 2007
      Unable to uninstall either of them in safe mode. McAfee is my primary virus softare - has been running for a while. BitDefender was only loaded so as to create a rescue CD for a friend. When BD was intalling, windows XP also did some updates. The two of them hung up and I had to (much to my pain) reboot (however - FYI - after the BitDefender install hung up, I did try to Cancel it and it did attempt to do a rollback, with the backwards progress bar, etc and it looked as if it completed. but the PC was still hung up, so I had to reboot.) Thus began the problem. Bottom line - at the moment I can't uninstall either of them in safe mode. -max
    • TroganTrogan London, UK
      edited January 2007
      Lets run AVG anti-spyware. You may have run it already, but I'd like to run it once more.
        Open AVG anti-spyware
      • On the main screen under Your Computer's security.
        • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
        • Wait until you see the Update succesfull message.
      • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
      • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
      If you are having problems with the updater, you can use this link to manually update ewido.
      AVG Anti-Spyware manual updates.
      Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

      Reboot your computer in Safe Mode.
      • If the computer is running, shut down Windows, and then turn off the power.
      • Wait 30 seconds, and then turn the computer on.
      • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
      • Ensure that the Safe Mode option is selected.
      • Press Enter. The computer then begins to start in Safe mode.
      • Login on your usual account.
      Once in Safe Mode:

      Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
      • Click on Scanner on the toolbar.
      • Click on the Settings tab.
        • Under How to act?
          • Click on Recommended Action and choose Quarantine from the popup menu.
        • Under How to scan?
          • All checkboxes should be ticked.
        • Under Possibly unwanted software:
          • All checkboxes should be ticked.
        • Under Reports:
          • Select Automatically generate report after every scan and uncheck Only if threats were found.
        • Under What to scan?
          • Select Scan every file.
      • Click on the Scan tab.
      • Click on Complete System Scan to start the scan process.
      • Let the program scan the machine.
      • When the scan has finished, follow the instructions below.
        IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
        • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
        • At the bottom of the window click on the Apply all Actions button. (3)
          scanavgjk2.jpg
      • When done, click the Save Scan Report button. (4)
        • Click the Save Report as button.
        • Save the report to your Desktop.
      • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes
      Please post the log back here, along with a new HijackThis log.
    • edited January 2007
      Thanks for not giving up on this one Trogan - here are the logs. -max

      AVG Anti-Spyware - Scan Report
      + Created at: 4:36:43 PM 1/12/2007

      + Scan result:

      Nothing found.

      ::Report end
      ================

      Logfile of HijackThis v1.99.1
      Scan saved at 4:51:58 PM, on 1/12/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\HJT\Analyse.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
      O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
      O4 - HKLM\..\Run: [SDFix] C:\SDFix\RunThis.bat /second
      O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://downloads.ewido.net/ewidoOnlineScan.cab
      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/download/scanner/wlscbase8460.cab
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1156438812346
      O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
      O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
      O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
      O16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) - http://www.seagate.com/support/disc/asp/tools/en/bin/npseatools.cab
      O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30155.www3.hp.com/ediags/hpfix/aio/en/check/qdiagh.cab?326
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service (file missing)
      O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
      O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
      O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
      O23 - Service: Machine Debug Manager (MDM) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (file missing)
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
      O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender10\vsserv.exe" /service (file missing)
      O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing)
    • TroganTrogan London, UK
      edited January 2007
      Hmm...we need to get Normal Mode working again...

      1. Download this file to your Desktop- combofix.exe
      2. Double click combofix.exe & follow the prompts.
      3. When finished, it shall produce a log for you. Post that log in your next reply

      Note:
      Do not mouseclick combofix's window whilst it's running. That may cause it to stall
    Sign In or Register to comment.