This thread's last reply is from August 4, 2010, 7:23 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
bkeesing
ESET would not run on the effected computer,,followed your instructions and it opened a new screen, light blue in color but did not seem to do anything. Light blue page is totally blank except for a tiny white box woth a red x in the upper left corner of the page. Not sure if this is an issue,,,but at this point it appears that I have no Java running on that computer. Was instructed to delete previous versions of Java in preparation for the updated version that has refused to load.
bkeesing
finally got Java to load on the affected computer, the Java test says its working now. Checked a movie clip on youtube and those still wont play,,, tried downloading an update to the inbedded player as suggested on the sire, but it returned a message that it could not find the site.
Prior to getting it installed I ran RKILL,,,there was nothing listed on the report.
Kaspersky online scanner is now working,,,running it now and will have a report when its done.
deltalima
OK thanks for letting me know, post when ready (the scan can take a long time).
bkeesing
Here are the scan results from Kaspersky
KASPERSKY ONLINE SCANNER 7.0: scan report
Monday, August 2, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Monday, August 02, 2010 15:12:43
Records in database: 4162558
Scan settings
scan using the following database extended
Scan archives yes
Scan e-mail databases yes
Scan area My Computer
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\
Scan statistics
Objects scanned 268913
Threats found 5
Infected objects found 6
Suspicious objects found 0
Scan duration 04:21:40
File name Threat Threats count
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\Microsoft\Outlook\Outlook.pst Infected: Trojan.HTML.Agent.dc 1
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\hQMy.exe Infected: Trojan.Win32.FakeAV.aw 1
C:\Program Files\Trend Micro\Antivirus\VSSBBR07.005 Infected: Trojan-Downloader.Win32.Agent.auv 1
C:\WINDOWS\Temp\jar_cache3301456097426842156.tmp Infected: Exploit.Java.Agent.bq 1
E:\I386\APPS\APP24087\src\CompaqPresario_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 1
E:\I386\APPS\APP24087\src\HPPavillion_Spring06.exe Infected: not-a-virus:AdWare.Win32.WeatherBug.a 1
Selected area has been scanned.
bkeesing
On the restart after running OLT,,, the windows screen (the one before the sign-in screen) opened for a few seconds, then went to a full screen of colored boxes, then a second pattern of colored small shapes,, the mouse is working, but it has stopped loading windows.
deltalima
Hi bkeesing,
Boot into Safe Mode:
Restart your computer and immediately begin tapping the F8 key on your keyboard.
If done right a Windows Advanced Options menu will appear. Select the Safe Mode option and press Enter.
Please run a new scan with OTL and post the contents of OTL.TXT
bkeesing
Was tapping F8 but it bypassed and went directly to a normal boot up,,,which worked normally, not sure what had happened. Below is the log for OLT from just before the re-boot. Do you still want another OLT scan run?
All processes killed
========== FILES ==========
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\hQMy.exe moved successfully.
C:\WINDOWS\Temp\jar_cache3301456097426842156.tmp moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 41 bytes
User: HP_Administrator
->Temp folder emptied: 1179901689 bytes
->Temporary Internet Files folder emptied: 46120578 bytes
->Java cache emptied: 21766636 bytes
->Flash cache emptied: 364531 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 40551299 bytes
->Flash cache emptied: 5195 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 35595104 bytes
->Java cache emptied: 14 bytes
->Flash cache emptied: 21525 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 16913015 bytes
%systemroot%\System32\dllcache .tmp files removed: 17303040 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 132515951 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 64684810 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 194398 bytes
Total Files Cleaned = 1,484.00 mb
OTL by OldTimer - Version 3.2.9.1 log created on 08032010_083347
Files\Folders moved on Reboot...
File\Folder C:\Documents and Settings\HP_Administrator\Local Settings\Temp\hsperfdata_HP_Administrator\3964 not found!
Registry entries deleted on Reboot...
bkeesing
OK, here is the report
RkU Version: 3.8.388.590, Type LE (SR2)
==============================================
OS Name: Windows XP
Version 5.1.2600 (Service Pack 3)
Number of processors #2
==============================================
>Stealth
==============================================
==============================================
>Files
==============================================
!-->[Hidden] C:\Documents and Settings\All Users\Application Data\Real\setup\config.ini::$DATA
==============================================
>Hooks
==============================================
ntkrnlpa.exe+0x0006ECAE, Type: Inline - RelativeJump 0x80545CAE-->80545CB5 [ntkrnlpa.exe]
[268]explorer.exe-->advapi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77DD1218-->00000000 [shimeng.dll]
[268]explorer.exe-->gdi32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x77F110B4-->00000000 [shimeng.dll]
[268]explorer.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x01001268-->00000000 [shimeng.dll]
[268]explorer.exe-->shell32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7C9C15A4-->00000000 [shimeng.dll]
[268]explorer.exe-->user32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x7E41133C-->00000000 [shimeng.dll]
[268]explorer.exe-->wininet.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x3D931480-->00000000 [shimeng.dll]
[268]explorer.exe-->ws2_32.dll-->kernel32.dll-->GetProcAddress, Type: IAT modification 0x71AB109C-->00000000 [shimeng.dll]
bkeesing
not sure why or if its important,,but on the rootkit unhooker program report it says at the end of the report:
!!POSSIBLE ROOTKIT ACTIVITY DETECTED!! =)
but it was not on the report when I saved or sent it to you
bkeesing
Everything seems to be working normally,
I sincerely appreciate your work and patience. This is am amazing service you provide.