IRC/SdBot.AFN

Discussion in 'adware, spyware & hijack cleaning' started by Mega, Jul 17, 2004.

Thread Status:
Not open for further replies.
  1. Mega

    Mega Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    4
    My NOD32 is saying I have the above virus in the msconfig.exe file. It can't clean nor delete the virus. Also it is now showing in resident memory. I have done the following:

    Installed and run adaware6 and found about 25 things.

    SPybot was already installed but found another 5 after scanning.

    I ran TDS3 and got the following log. I'd appreciate being told how to get rid of this virus. Thanks in anticipation.


    Logfile of HijackThis v1.97.7
    Scan saved at 1:46:20 PM, on 17/07/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Sygate\SPF\smc.exe
    E:\WINDOWS\Explorer.EXE
    E:\WINDOWS\system32\spoolsv.exe
    E:\Program Files\Telstra\Cable Login\bpcable.exe
    E:\WINDOWS\System32\msconfg.exe
    E:\WINDOWS\System32\Winsreg32.exe
    E:\WINDOWS\System32\atiphexx.exe
    E:\WINDOWS\System32\igfxtray.exe
    E:\WINDOWS\System32\hkcmd.exe
    E:\Program Files\Eset\nod32kui.exe
    E:\WINDOWS\System32\WinFixd32.exe
    E:\Program Files\MSN Messenger\MsnMsgr.Exe
    E:\Program Files\Eset\nod32krn.exe
    E:\PROGRA~1\ICQ\ICQ.exe
    E:\WINDOWS\System32\wuauclt.exe
    E:\Master\HijackThis.exe
    E:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\WINDOWS\system32\notepad.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...aults/sb/*http://www.yahoo.com/search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
    O1 - Hosts: 64.91.255.87 www.dcsresearch.com
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [BigPondCable] "E:\Program Files\Telstra\Cable Login\bpcable.exe" /r
    O4 - HKLM\..\Run: [Microsoft Updater Resources] WinFixd32.exe
    O4 - HKLM\..\Run: [Microsoft Update] msconfg.exe
    O4 - HKLM\..\Run: [Microsoft Update Machine] Winsreg32.exe
    O4 - HKLM\..\Run: [ati control panel] atiphexx.exe
    O4 - HKLM\..\Run: [IgfxTray] E:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] E:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [nod32kui] "E:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SmcService] E:\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [Mirabilis ICQ] E:\PROGRA~1\ICQ\ICQNet.exe
    O4 - HKLM\..\RunServices: [Microsoft Updater Resources] WinFixd32.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Machine] Winsreg32.exe
    O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe
    O4 - HKCU\..\Run: [Microsoft Update] msconfg.exe
    O4 - HKCU\..\Run: [Microsoft Updater Resources] WinFixd32.exe
    O4 - HKCU\..\Run: [ati control panel] atiphexx.exe
    O4 - HKCU\..\Run: [Microsoft Update Machine] Winsreg32.exe
    O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: ICQ Pro (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O10 - Broken Internet access because of LSP provider 'imon.dll' missing
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38178.9650810185
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Thanks for any help you can give.

    Kate
     
  2. Marianna

    Marianna Spyware Fighter

    Joined:
    Apr 23, 2002
    Posts:
    1,215
    Location:
    B.C. Canada
    Hi Kate

    Press Ctrl+Alt+Del and 'end task' on any of the follow that are present:

    WinFixd32.exe
    msconfg.exe
    Winsreg32.exe

    Have Hijack This fix the following by placing a check in the appropriate boxes and selecting fix checked.
    Make sure all browser and all Windows Explorer windows are closed before fixing

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus.../search/ie.html
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/cus...//www.yahoo.com
    O1 - Hosts: 64.91.255.87 www.dcsresearch.com

    O4 - HKLM\..\Run: [Microsoft Updater Resources] WinFixd32.exe
    O4 - HKLM\..\Run: [Microsoft Update] msconfg.exe
    O4 - HKLM\..\Run: [Microsoft Update Machine] Winsreg32.exe

    O4 - HKLM\..\RunServices: [Microsoft Updater Resources] WinFixd32.exe
    O4 - HKLM\..\RunServices: [Microsoft Update] msconfg.exe
    O4 - HKLM\..\RunServices: [Microsoft Update Machine] Winsreg32.exe

    O4 - HKCU\..\Run: [Microsoft Update] msconfg.exe
    O4 - HKCU\..\Run: [Microsoft Updater Resources] WinFixd32.exe
    O4 - HKCU\..\Run: [Microsoft Update Machine] Winsreg32.exe
    O4 - Global Startup: Microsoft Office.lnk = E:\Program Files\Microsoft Office\Office10\OSA.EXE

    Then reboot and use AdAware as described :
    HERE

    Then use the Disk Cleanup Utility to empty all your Temp folders.

    Then Disable system restore: Instructions here
    Reboot

    Enable System Restore.

    Problem gone??

    btw - pls. go to Windows Update and get ALL critical updates !
     
  3. Mega

    Mega Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    4
    :'( I have done what you said but still nod32 tells me that I have IRC/SdBot.AFN in the same place. It is no longer in the memory. This is the new log from hijack

    Logfile of HijackThis v1.97.7
    Scan saved at 9:23:22 PM, on 19/07/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Sygate\SPF\smc.exe
    E:\WINDOWS\Explorer.EXE
    E:\WINDOWS\system32\spoolsv.exe
    E:\Program Files\Eset\nod32krn.exe
    E:\Program Files\Telstra\Cable Login\bpcable.exe
    E:\WINDOWS\System32\atiphexx.exe
    E:\WINDOWS\System32\igfxtray.exe
    E:\WINDOWS\System32\hkcmd.exe
    E:\Program Files\Eset\nod32kui.exe
    E:\Program Files\MSN Messenger\MsnMsgr.Exe
    E:\PROGRA~1\ICQ\ICQ.exe
    E:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\Master\HijackThis.exe
    E:\Master\HijackThis.exe

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [BigPondCable] "E:\Program Files\Telstra\Cable Login\bpcable.exe" /r
    O4 - HKLM\..\Run: [ati control panel] atiphexx.exe
    O4 - HKLM\..\Run: [IgfxTray] E:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] E:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [nod32kui] "E:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SmcService] E:\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [Mirabilis ICQ] E:\PROGRA~1\ICQ\ICQNet.exe
    O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe
    O4 - HKCU\..\Run: [ati control panel] atiphexx.exe
    O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: ICQ Pro (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O10 - Broken Internet access because of LSP provider 'imon.dll' missing
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38178.9650810185
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Please Help
    Mega
     
  4. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,350
    Location:
    The Netherlands
    Check, and have Hijack This fix these items:

    O4 - HKLM\..\Run: [ati control panel] atiphexx.exe
    O4 - HKLM\..\RunServices: [ati control panel] atiphexx.exe
    O4 - HKCU\..\Run: [ati control panel] atiphexx.exe

    Restart your computer, find and delete atiphexx.exe, if still there.

    The file could possibly have the "Hidden" attribute. Here's how to show hidden and operating system files

    When done, post a fresh log.
     
  5. Mega

    Mega Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    4
    Ok have done the steps you have said to do, but when I run nod32 this is the results.

    Scanning Log
    NOD32 version 1.817 (20040719) NT
    Command line: E:\WINDOWS
    Checking CRC of the NOD32.EXE file: status OK
    Operating memory is OK.

    date: 20.7.2004 time: 14:56:51
    Scanned disks, directories and files: E:\WINDOWS\
    E:\WINDOWS\system32\msconfg.exe »UPX v12_m5 - IRC/SdBot.AFN trojan
    number of files scanned: 23769
    number of viruses found: 1
    time of completion: 15:01:51 total scanning time: 300 sec (00:05:00)

    This is the log from HijackThis

    Logfile of HijackThis v1.97.7
    Scan saved at 3:33:41 PM, on 20/07/2004
    Platform: Windows XP (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

    Running processes:
    E:\WINDOWS\System32\smss.exe
    E:\WINDOWS\system32\winlogon.exe
    E:\WINDOWS\system32\services.exe
    E:\WINDOWS\system32\lsass.exe
    E:\WINDOWS\system32\svchost.exe
    E:\WINDOWS\System32\svchost.exe
    E:\Sygate\SPF\smc.exe
    E:\WINDOWS\system32\spoolsv.exe
    E:\Program Files\Telstra\Cable Login\bpcable.exe
    E:\WINDOWS\System32\igfxtray.exe
    E:\WINDOWS\System32\hkcmd.exe
    E:\Program Files\Eset\nod32kui.exe
    E:\Program Files\Eset\nod32krn.exe
    E:\PROGRA~1\ICQ\ICQ.exe
    E:\Program Files\Internet Explorer\IEXPLORE.EXE
    E:\WINDOWS\explorer.exe
    E:\Master\HijackThis.exe

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - E:\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - E:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [BigPondCable] "E:\Program Files\Telstra\Cable Login\bpcable.exe" /r
    O4 - HKLM\..\Run: [IgfxTray] E:\WINDOWS\System32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] E:\WINDOWS\System32\hkcmd.exe
    O4 - HKLM\..\Run: [nod32kui] "E:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
    O4 - HKLM\..\Run: [SmcService] E:\Sygate\SPF\smc.exe -startgui
    O4 - HKLM\..\Run: [Mirabilis ICQ] E:\PROGRA~1\ICQ\ICQNet.exe
    O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: ICQ Pro (HKLM)
    O9 - Extra 'Tools' menuitem: ICQ (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
    O10 - Broken Internet access because of LSP provider 'imon.dll' missing
    O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab28578.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38178.9650810185
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

    Thanks Mega
     
  6. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,350
    Location:
    The Netherlands
    That's a clean log; I take it NOd32 quarantained or deleted that file, so you should be good to go now. :)
     
  7. Mega

    Mega Registered Member

    Joined:
    Jul 17, 2004
    Posts:
    4
    No Nod32 has no option to do anything but leave.
    So when you run nod it reports the IRC/SdBpt.AFN
     
  8. TonyKlein

    TonyKlein Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    4,350
    Location:
    The Netherlands
    Well, try booting into Safe Mode, and manually deleting the file; that shouldn't be a prob.
     
Thread Status:
Not open for further replies.