worm/virus attack - Techist - Tech Forum

Go Back   Techist - Tech Forum > Computer Software > Microsoft Windows and Software
Click Here to Login
Closed Thread
Thread Tools Display Modes
Old 01-09-2004, 11:58 PM   #1 (permalink)
Newb Techie
Join Date: Jan 2004
Posts: 3
Unhappy worm/virus attack

Help! I know that I have a virus or worm in my system, since yeseterday, my system generated an error message referring to the rpc service and nt authority system and did a spontaneous shutdown. I went to the rpc service properties, then recovery, and set all failures to "take no action" to stop the spontaneous shutdown. I had the same symptom last month 'coz my system was infected by the nachi worm. But I got rid of it using my AVG antivirus program and the stinger.exe removal tool from McAfee. But now, I can't get rid of whatever this virus/worm is 'coz I don't know what it is! I already updated my AVG, ran it, and I also ran almost all the virus removal tools from Symantec and McAfee, to no avail. I scanned for spyware using Spybot and it got rid of all the spyware and adware it detected. I also checked all the processes that were running in my system, and they seem to be valid. Finally, I ran HijackThis and here's the log. Please tell me what could have infected my system. Please, please, pleasssse!!! I don't wanna have to reformat my hard drive. Thanks in advance

Logfile of HijackThis v1.97.7
Scan saved at 12:22:54 PM, on 1/10/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Alset\HelpExpress\Roanne\HXDL.EXE
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE

O2 - BHO: SysShield IE Popup Blocker - {9A23B8A4-C6C9-4A68-8FA6-5F905DC8FF80} - C:\Program Files\SysShield Tools\Internet Eraser\PKExt.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [CreativeMixer] C:\Program Files\Creative\Audio2K\PROGRAM\CTMIX32.EXE /t
O4 - HKLM\..\Run: [CHotKey] GeniusKB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [HELPEXP.EXE] C:\Program Files\Alset\HelpExpress\Roanne\Client\HelpExp.exe
O4 - HKCU\..\Run: [HXDL.EXE] C:\Program Files\Alset\HelpExpress\Roanne\HXDL.EXE -from="HXIUL.EXE" -to="HXIUL.EXE"
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Download with NetPumper - C:\Program Files\NetPumper\AddUrl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Create Mobile Favorite (HKLM)
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O9 - Extra button: CuteShield Internet Eraser (HKCU)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...ctor/swdir.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://active.macromedia.com/flash2/cabs/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8510B699-9C96-49EA-9175-FB4765BEC5A6}: NameServer =

2003crush is offline  
Old 01-10-2004, 12:05 AM   #2 (permalink)
Junior Techie
Join Date: Dec 2003
Posts: 99

do you have the blaster update

nomad is offline  
Old 01-10-2004, 12:15 AM   #3 (permalink)
Newb Techie
Join Date: Jan 2004
Posts: 3

Yes, I do. I've already installed the security patch and run the removal tool, but it didn't find anything. Do you have any other idea what it could be? Thanks =)
2003crush is offline  
Old 01-10-2004, 08:01 PM   #4 (permalink)
True Techie
Join Date: May 2003
Posts: 221

Do you have any idea as to what C:\WINDOWS\GeniusKB.exe might be ?

You can also have hijack fix
O4 - HKCU\..\Run: [HELPEXP.EXE] C:\Program Files\Alset\HelpExpress\Roanne\Client\HelpExp.exe
O4 - HKCU\..\Run: [HXDL.EXE] C:\Program Files\Alset\HelpExpress\Roanne\HXDL.EXE -from="HXIUL.EXE" -to="HXIUL.EXE"
mobo is offline  
Old 01-11-2004, 06:51 AM   #5 (permalink)
Newb Techie
Join Date: Jan 2004
Posts: 3

Yes, I've turned off system restore. And I'm pretty sure it's not the blaster worm anymore since I've run the removal tool twice and it didn't find the blaster worm in my system. Does any of those items in my hijackthis log seem like a virus file? Oh, and the geniuskb.exe actually refers to my keyboard driver 'coz i have a genius multimedia keyboard.
2003crush is offline  
Old 01-11-2004, 08:26 AM   #6 (permalink)
True Techie
Join Date: May 2003
Posts: 221

Nothing malicious in or currently showing up in your hjt log.
mobo is offline  
Old 01-12-2004, 02:03 AM   #7 (permalink)
Techie Beyond Description
Apokalipse's Avatar
Join Date: Jun 2003
Location: Melbourne, Australia
Posts: 14,559

my cousin used to work for Genius selling cameras and related stuff.
maybe if it has caused damage you could try a repair install, also try what Microbell said and do a restore and remove the restoration files and tell us if it helps
Apokalipse is offline  
Old 01-12-2004, 08:09 AM   #8 (permalink)
True Techie
Join Date: May 2003
Posts: 221

Originally posted by MicroBell
I'm not sure this has a bareing on you..but be advised there are 6 versions of the blaster worm...and if the wrong removal tool is used it will not remove or find it. Your log file...looks fine.

As well there is another trojan on the prowl with the same symptoms I cleaned up for a poster a couple weeks back.
mobo is offline  
Old 01-12-2004, 06:47 PM   #9 (permalink)
Junior Techie
Join Date: Nov 2003
Posts: 73

The problem sounds like the new virus Agobot. It is very similiar to the Blaster virus and acts just like it but AVG should find it and remove it. I had a hard time removing it from a couple of computers that I was working on at my shop. Are you sure that AVG is actually updating I had a problem with that also. The Agobot virus will shutdown antivirus programs a cause all kinds of havoc on a computer.
mitschej is offline  
Old 01-13-2004, 12:25 AM   #10 (permalink)
Ultra Techie
Join Date: Jan 2004
Posts: 872

Agree with all the suggestions .. Just wanted to add on .. Enable ICF (Internet Connection Firewall) n' disable System Restore ..Before running the Clean up tool ..

Ur Logs seem to be all normal elsewise

Screenshots of my Desktop.....Post ur\'s too :D

AMD AthlonXP3000+@ 2.2GHz, Cooler Master Aero 7+, Gigabyte 7NNXP , 1GB Kingston HyperX PC3200 Dual Channel , MSI FX5600 VTDR 256 ,Pinnacle PCTV , 120+120GB Barracuda , Liteon 52x CDRW , Samsung DVDROM , Benq DW1620 16x DVD ReWriter, Phillips 21\" TV,Samsung Syncmaster 763MB,Logitech Cordless MX DUO , Thermaltake Silent PurePower 480W Butterfly Series PSU, Win XP SP2,RH9.
Creative DDTS100 Decoder, Creative Inspire TD7700 7.1 Speakers

Search TF B4 u post { Thanks for this one! Emily :) }
<form action=\"http://www.theriddlehouse.com/random/tfsearch.php\"><input type=\"text\" name=\"search\"><input type=\"submit\" name=\"submit\" value=\"Search!\"></form>
preet2u is offline  
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Copyright 2002- Social Knowledge, LLC All Rights Reserved.

All times are GMT -5. The time now is 12:59 AM.

Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2017, vBulletin Solutions, Inc.