Author Topic: malware type--- dropper  (Read 18556 times)

0 Members and 1 Guest are viewing this topic.

someday

  • Guest
Re: malware type--- dropper
« Reply #15 on: October 06, 2009, 06:35:16 PM »
sorry...what is bsod?? is that some sort of malware???

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: malware type--- dropper
« Reply #16 on: October 06, 2009, 06:36:52 PM »
see this :http://en.wikipedia.org/wiki/Blue_Screen_of_Death (click on the picture.)

someday

  • Guest
Re: malware type--- dropper
« Reply #17 on: October 06, 2009, 06:40:11 PM »
no sir..

CharleyO

  • Guest
Re: malware type--- dropper
« Reply #18 on: October 07, 2009, 09:55:51 AM »
***

An analysis of your HJT log shows the following problems :

We couldn't detect any active process of a firewall on your system. Possible reasons:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don't use any firewall at all.
We recommend you to use a firewall.

Platform: Windows XP SP2 (WinNT 5.01.2600)
A newer version of service pack is available. Service packs increase the safety of your system. Visit Microsoft's windowsupdate site to download the newest version of the service pack.

MSIE: Internet Explorer v7.00 (7.00.5730.0013)
IE8 has been out for many months and is more secure than IE7.

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
Unnecessary (deactivated) entry that can be fixed.

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - (no file)
Unnecessary (deactivated) entry that can be fixed.

O16 - DPF: {74E4A24D-5224-4F05-8A41-99445E0FC22B} (GameHouse Games Player) - http://www.gamehouse.com/games/gamehouse/ghplayer.cab
Check if you know this site and fix it if you do not. Unknown ActiveX-Objects, or ActiveX-Objects from unknown sites should always be fixed.

O17 - HKLM\System\CCS\Services\Tcpip\..\{FC412536-8230-4658-B7C4-30228A848A82}: NameServer = 192.172.1.1,202.56.215.54
Do you know the IP or Domain '192.172.1.1,202.56.215.54'? If not, fix this entry.
This is probably your ISP but you should check it to be sure.

O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\
This is a fake Windows Update AutoUpdate Service and should be fixed.
Items listed as 023 are listings of non-Microsoft services. The list should be the same as the one you see in the Msconfig utility of Windows XP. Several trojan hijackers use a homemade service in adittion to other startups to reinstall themselves. The full name is usually important-sounding, like 'Network Security Service', 'Workstation Logon Service' or 'Remote Procedure Call Helper' or, as in this case, Windows Update AutoUpdate Service.
http://www.threatexpert.com/files/wuauserv.dll.html



Overview of running tasks :

smss.exe   
System task   
Session Manager Subsystem

winlogon.exe   
System task   
Microsoft Windows Logon Process

services.exe   
System task   
Windows Service Controller

lsass.exe   
System task   
Local Security Authority Service

svchost.exe   
System task   
Microsoft Service Host Process

svchost.exe   
System task   
Microsoft Service Host Process

aswUpdSv.exe   
Virusscan   
Avast Anti-Virus Component

ashServ.exe   
Virusscan   
Avast

Explorer.EXE   
System task   
Microsoft Windows Explorer

igfxtray.exe   
Application   
Intel Graphics configuration and diagnostic application

hkcmd.exe   
Application   
Intel multimedia devices

igfxpers.exe   
Driver   
Intel Common User Interface Module

SOUNDMAN.EXE   
Backgroundtask   
Realtek Avance Logic Inc

igfxsrvc.exe   
Driver   
Intel(R) Common User Interface

ashDisp.exe   
Virusscan   
Avast AntiVirus

jusched.exe   
Backgroundtask   
Sun Java Update Scheduler

realsched.exe   
Application   
RealNetworks Scheduler

flockbox.exe   
Unknown task   This security software from FSPro Labs allows you to password protect any folder on your                                   computer.
Unknown task    http://www.pcpitstop.com/libraries/process/i/flockbox.exe.html

DAP.EXE   
Backgroundtask   
Download Accelerator Plus from Speedbit.

ctfmon.exe   
System task   
Alternative User Input Services

spoolsv.exe   
System task   
Microsoft Printer Spooler Service

ashMaiSv.exe   
Virusscan   
Avast Anti-Virus Component

ashWebSv.exe   
Virusscan   
avast! Web Scanner

iexplore.exe   
Application   
Microsoft Internet Explorer

svchost.exe   
System task   
Microsoft Service Host Process

svchost.exe   
System task   
Microsoft Service Host Process

svchost.exe   
System task   
Microsoft Service Host Process

svchost.exe   
System task   
Microsoft Service Host Process

svchost.exe   
System task   
Microsoft Service Host Process

svchost.exe   
System task   
Microsoft Service Host Process

jucheck.exe   
Backgroundtask   
Sun Java UpdateChecker Module

HijackThis.exe   
Application   
Merijn Hijackthis


***
« Last Edit: October 07, 2009, 09:59:35 AM by CharleyO »

someday

  • Guest
Re: malware type--- dropper
« Reply #19 on: October 07, 2009, 02:07:46 PM »
thanks sir CharleyO for replying..i wud like you to see this as when i google this malware it said that it disables firewall and affects network settings..

plz tell me how can i free my pc from it???

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: malware type--- dropper
« Reply #20 on: October 07, 2009, 06:55:29 PM »
hello someday,

this profile :  http://forum.avast.com/index.php?action=profile;u=11091

send him a pm. with the link to this forum. he is good at removing rootkits. just message him.

nmb

someday

  • Guest
Re: malware type--- dropper
« Reply #21 on: October 08, 2009, 10:55:55 AM »
hello nmb..
i am not allowed to PM anyone!!!! are there any rules??
and one more thing now i cant connect to my internet in the normal mode..i replying while in the safe mode with networking...y so???is that becoz of that malware??this is really creating a problem..plz help before my pc is dead!!! ??? ???

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: malware type--- dropper
« Reply #22 on: October 08, 2009, 10:58:26 AM »
yes it is a forum rule.

sorry

oki i'll message him. hold on.

edit : i have sent him a message. he might come here around 6 pm(think so). be here at that time.
« Last Edit: October 08, 2009, 11:01:06 AM by nmb »

someday

  • Guest
Re: malware type--- dropper
« Reply #23 on: October 08, 2009, 11:08:37 AM »
thanks a lot...nmb...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: malware type--- dropper
« Reply #24 on: October 09, 2009, 12:13:53 AM »
Hi there lets have a look see and see what I can find

To ensure that I get all the information this log will need to be uploaded to Mediafire and post the sharing link.

Download OTS  to your Desktop
  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • Reg - Shell Spawning
    • Reg - NetSvcs
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EvtViewer (last 10)
    • Now click the Run Scan button on the toolbar.
    • Let it run unhindered until it finishes.
    • When the scan is complete Notepad will open with the report file loaded in it.
    • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

    someday

    • Guest
    Re: malware type--- dropper
    « Reply #25 on: October 09, 2009, 08:40:45 AM »
    @essexboy

    thanks for replying..i uploaded the scanfile to Mediafire and here is the sharing link..
    http://www.mediafire.com/?sharekey=75cfe340ef6c60dcc2b435915e8821d7e04e75f6e8ebb871

    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: malware type--- dropper
    « Reply #26 on: October 09, 2009, 06:50:31 PM »
    Prior to running this fix please create a restore point.  During the fix you will lose your taskbar and a reboot will be requested - this is normal

    Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

    Code: [Select]
    [Unregister Dlls]
    [Driver Services - Safe List]
    YY -> (synsend) synsend [Kernel | System | Running] ->
    [Registry - Safe List]
    < MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
    YN -> \{93f0a613-9e14-11de-8550-00e04c360659} ->
    YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93f0a613-9e14-11de-8550-00e04c360659}\Shell\AutoRun\command ->
    YN -> \{93f0a613-9e14-11de-8550-00e04c360659}\Shell\AutoRun\command\\"" -> [lcw.exe]
    YN -> \{93f0a613-9e14-11de-8550-00e04c360659} ->
    YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93f0a613-9e14-11de-8550-00e04c360659}\Shell\open\Command ->
    YN -> \{93f0a613-9e14-11de-8550-00e04c360659}\Shell\open\Command\\"" -> [lcw.exe]
    YN -> \{93f0a614-9e14-11de-8550-00e04c360659} ->
    YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93f0a614-9e14-11de-8550-00e04c360659}\Shell\AutoRun\command ->
    YN -> \{93f0a614-9e14-11de-8550-00e04c360659}\Shell\AutoRun\command\\"" -> H:\lcw.exe [H:\lcw.exe]
    YN -> \{93f0a614-9e14-11de-8550-00e04c360659} ->
    YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93f0a614-9e14-11de-8550-00e04c360659}\Shell\open\Command ->
    YN -> \{93f0a614-9e14-11de-8550-00e04c360659}\Shell\open\Command\\"" -> H:\lcw.exe [H:\lcw.exe]
    YN -> \{93f0a61b-9e14-11de-8550-00e04c360659} ->
    YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93f0a61b-9e14-11de-8550-00e04c360659}\Shell\AutoRun\command ->
    YN -> \{93f0a61b-9e14-11de-8550-00e04c360659}\Shell\AutoRun\command\\"" -> [lcw.exe]
    YN -> \{93f0a61b-9e14-11de-8550-00e04c360659} ->
    YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{93f0a61b-9e14-11de-8550-00e04c360659}\Shell\open\Command ->
    YN -> \{93f0a61b-9e14-11de-8550-00e04c360659}\Shell\open\Command\\"" -> [lcw.exe]
    [Files/Folders - Modified Within 30 Days]
    NY -> Winset.drv -> C:\WINDOWS\Winset.drv
    NY -> winkey.drv -> C:\WINDOWS\winkey.drv
    NY -> sayspqx -> C:\WINDOWS\System32\sayspqx
    NY -> anaunda -> C:\WINDOWS\System32\anaunda
    NY -> undatch -> C:\WINDOWS\System32\undatch
    [Empty Temp Folders]


    The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTS log.

    I will review the information when it comes back in.

    Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.


    someday

    • Guest
    Re: malware type--- dropper
    « Reply #27 on: October 10, 2009, 08:15:26 AM »
    @essexboy

    i did as u told..here is log file created after Fix..

    http://www.mediafire.com/file/jymoiint2qw/10102009_111117.log

    and this is the scanfile created after using OTS(after reboot)

    http://www.mediafire.com/file/zozoq3td2nt/OTS2.Txt

    This process went as you said..and about the problem with my computer that i will post when i will get one...
    thanks...


    Offline essexboy

    • Malware removal instructor
    • Avast Überevangelist
    • Probably Bot
    • *****
    • Posts: 40589
    • Dragons by Sasha
      • Malware fixes
    Re: malware type--- dropper
    « Reply #28 on: October 10, 2009, 03:17:06 PM »
    OK that was not strong enough to kill the rootkit

    Download Combofix from any of the links below. You must rename it before saving  rename it to Gotcha before saving it to your desktop.

    Link 1
    Link 2


    ==================================


    Double click on the renamed ComboFix.exe & follow the prompts.
      When finished, it will produce a report for you. 
    • Please post the C:\ComboFix.txt so we can continue cleaning the system.

    someday

    • Guest
    Re: malware type--- dropper
    « Reply #29 on: October 10, 2009, 05:02:35 PM »
    hello sir...
    i downloaded  and renamed it...when i had run the prog a blue window popped out and few sec later one more window saying...

    "This machine doesnt have Microsoft windows Recovery console installed, without it the combofix cant fix serious infections..click yes to download/install"

    what should i do??should i click yes??(just now i clicked no and then the cross button)