nickster Posted October 19, 2009 Report Share Posted October 19, 2009 Hello. I believe I have one or more trojans, viruses, and/or worms.Logging on in full mode can't get past the logon process. I get "Windows has closed Userinit Logon Application". I'll close that dialog box tnen within a few seconds, a dialog box says my system is being shut down initiated by NT AUTHORITY\SYSTEM and gives me a 60-second countdown before it starts to shut down. That allows me to shut open programs, but now I can't log on at all so have nothing open. A few days ago I could log on but when I opened the browser, the browser was unable open any pages. Now I can't even log on. In safe mode with networking, I'll either get the blue screen of death (which says IRQL_NOT_LESS_OR_EQUAL and the hex code it gives me varies).The code I got once was"0x0000008E (0xC0000005, 0x8A69D2B6, 0xB9399A30, 0x00000000), or the shut down initiated by NT AUTHORITY\SYSTEM message. I can log on to safe mode without networking but the log on process is slowed down (including cursor icon refreshing as I move the mouse) I can use my PC in this mode but burning DVDs is bogged down (write rate is about 500K/sec instead of upwards of 2000K/sec). In all modes, something disabled the sound card. I also noticed VLC media player doesn't show the video but will load the video file) One or more of the logs include in this post mention a Dll with "audio" in the name and a DLL with "video" in the name the dlls apparently are in a folder named "wsnpoem", but I don't see the folder in Explorer The malware (whatever it is) creates files in system32\temp such as "1.TMP", "2.TMP", etc. I have included my HijackThis log with the entries of what it says will be deleted on reboot. I included the hijackthis startup log (I suspect the malware is hiding some entries from showing up. I ran Malwarebytes and included the log, Hijackthis log text:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 21:26:52, on 10/18/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: Safe modeRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\dmadmin.exeC:\WINDOWS\Explorer.EXEC:\Program Files\ImgBurn\ImgBurn.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shortcut365.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shortcut365.com/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul...//www.yahoo.comF2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dllO3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dllO3 - Toolbar: ZoneAlarm Spy Blocker Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dllO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [PCTAVApp] "C:\Program Files\PC Tools AntiVirus\PCTAV.exe" /MONITORSCANO4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscriptO4 - HKLM\..\Run: [3053] C:\WINDOWS\system32\23.tmp.exeO4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silentO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKUS\S-1-5-18\..\Run: [Login Software 2009] C:\WINDOWS\TEMP\hpd6u861.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [Login Software 2009] C:\WINDOWS\TEMP\hpd6u861.exe (User 'Default user')O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO8 - Extra context menu item: &Search - ?p=ZLfox000O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - http://www.superadblocker.com/activex/sabspx.cabO16 - DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.6.0_10) - O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} (Java Plug-in 1.6.0_11) - O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (file missing)O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\O22 - SharedTaskScheduler: iukjsf8w3jirojs9f8u3jruhsf78s3jijdif - {A249BC15-23F2-42AD-F4E4-00AAC39C0004} - (no file)O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exeO23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe (file missing)O23 - Service: Dot3svc - Unknown owner - C:\WINDOWS\TEMP\VRT11.tmp (file missing)O23 - Service: fastnetsrv - Unknown owner - C:\WINDOWS\TEMP\VRTE.tmpO23 - Service: FastUserSwitchingCompatibility - Unknown owner - C:\WINDOWS\TEMP\VRTA.tmp (file missing)O23 - Service: Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Unknown owner - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exeO23 - Service: gupdate1c9a33a61b59fa - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exeO23 - Service: gusvc - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: ImapiService - Unknown owner - C:\WINDOWS\system32\imapi.exe (file missing)O23 - Service: JavaQuickStarterService - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXEO23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifSvc.exeO23 - Service: Media Center Extender Service (McrdSvc) - Unknown owner - C:\WINDOWS\ehome\mcrdsvc.exeO23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - C:\WINDOWS\system32\msdtc.exe (file missing)O23 - Service: MyWebSearchService - Unknown owner - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe (file missing)O23 - Service: Net_Login - Unknown owner - C:\WINDOWS\svchust.exe (file missing)O23 - Service: PCTAVSvc - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exeO23 - Service: PrismXL - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)O23 - Service: RDSessMgr - Unknown owner - C:\WINDOWS\system32\sessmgr.exe (file missing)O23 - Service: Remote Procedure Call (RPC) Locator (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)O23 - Service: RSVP - Unknown owner - C:\WINDOWS\system32\rsvp.exeO23 - Service: Smart Card (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe (file missing)O23 - Service: SPAZXOSCFXYDK - Sysinternals - www.sysinternals.com - C:\DOCUME~1\Owner.NJR\LOCALS~1\Temp\SPAZXOSCFXYDK.exeO23 - Service: Spooler - Unknown owner - C:\WINDOWS\system32\spoolsv.exe (file missing)O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exeO23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)O23 - Service: vsmon - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exeO23 - Service: VSS - Unknown owner - C:\WINDOWS\System32\vssvc.exeO23 - Service: WmiApSrv - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------Malwarebytes log text:Malwarebytes' Anti-Malware 1.41Database version: 2775Windows 5.1.2600 Service Pack 3 (Safe Mode)10/17/2009 9:33:15 PMmbam-log-2009-10-17 (21-33-15).txtScan type: Full Scan (C:\|D:\|)Objects scanned: 253306Time elapsed: 2 hour(s), 43 minute(s), 47 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 1Registry Values Infected: 12Registry Data Items Infected: 3Folders Infected: 6Files Infected: 60Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Data Items Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows\system32\ntos.exe -> Delete on reboot.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: system32\ntos.exe -> Delete on reboot.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,) Good: (Userinit.exe) -> Quarantined and deleted successfully.Folders Infected:C:\WINDOWS\system32\wsnpoem (Trojan.Agent) -> Delete on reboot.Files Infected:C:\WINDOWS\system32\wsnpoem\audio.dll (Trojan.Agent) -> Delete on reboot.C:\WINDOWS\system32\wsnpoem\video.dll (Trojan.Agent) -> Delete on reboot.C:\WINDOWS\system32\ntos.exe (Backdoor.Bot) -> Delete on reboot.-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Quote Link to comment Share on other sites More sharing options...
Belatucadrus Posted October 19, 2009 Report Share Posted October 19, 2009 I don't think we have any Hijack log readers on forum at the moment. You could try burning the DrWeb CureIT Live CD to disk and running that. Quote Link to comment Share on other sites More sharing options...
Dencandy Posted October 20, 2009 Report Share Posted October 20, 2009 This link here (MALEKTIPS) has a list of sites that can help you with analysing HijackThis logs. It looks to me like you have multiple infections on your computer and it might be quicker to reinstall the operating system and start from scratch. Quote Link to comment Share on other sites More sharing options...
-pops- Posted October 20, 2009 Report Share Posted October 20, 2009 The thing that I instantly recognised is the NT AUTHORITY shutdown notice. This points to the Blaster worm which is very old and makes me thing that your security software is not working properly. It does seem odd, though, that the Blaster worm is present as it was fixed in an MS patch long before XPSP3 came out.This link tells you how to stop the Blaster worm shutting your machine down but this is only a temporary fix before taking more drastic action http://en.wikipedia.org/wiki/Blaster_%28computer_worm%29 (Method at the end of the article).I agree with Dencandy that you have multiple infections and it would be easier to re-install your system afresh rather than patching up which almost always leaves some residues around preventing the machine operating at its best. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.