|
|
#1 (permalink) |
|
Silver Member
![]() Join Date: Oct 2005
Age: 22
Posts: 110
|
There is supposed to a very deadly virus in my college network to which i am connected. I am not sure about the name of the virus but it may be something like Michaelangangelo or something.A guy's comp got infected and he had to replace his HDD.The virus is supposedly a bootsector virus and is not detected by any antivirus software.I have Norton 2006,Sypbot and Ad-Aware but the scans have not yielded anything.
I dont know whether the virus exists really or not.The infected comps had audio drivers corrupted in the first stage i.e the people were not able to play music files although normal Windows sounds(logon,logoff etc) could be heard. My comp doesnt have any problems as of now.I am attaching my Hijack this log here.Do i need to format the HDD to be on the safe side. Isnt there any other way to find out whether a comp is infected or not? Please help HJT log: Logfile of HijackThis v1.99.1 Scan saved at 3:54:49 PM, on 10/1/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZONELABS\vsmon.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\WINDOWS\system32\taskswitch.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\WINDOWS\system32\taskmgr.exe C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Program Files\WinAce\WinAce.exe C:\Documents and Settings\Admin\My Documents\Downloads\Compressed\hijackthis\HijackTh is.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [Active Desktop Calendar] C:\Program Files\XemiComputers\Active Desktop Calendar\ADC.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot O4 - Startup: Adobe Gamma.lnk.disabled O4 - Global Startup: Vypress Chat StartUp.lnk.disabled O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk.disabled O4 - Global Startup: Vypress Chat StartUp.lnk = ? O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Download All Links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download web site with Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{0B3AD9DD-74E3-4A81-88C8-0DFAEA3343A9}: NameServer = 172.16.200.3,60.0.0.5 O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB701\webserver\bin\win32\matlabserver.exe O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing) O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe |
|
|
|
|
|
#2 (permalink) |
|
Administrator
![]() Join Date: Apr 2005
Location: London
Age: 26
Posts: 9,169
|
looks clean,
and the Michelangelo virus is 14 years old, and not a problem anymore
__________________
What did one snow man say to the other? can you smell carrot? The fight is won or lost far away from witnesses - behind the lines, in the gym, and out there on the road, long before I dance under those lights. How you do anything, is how you do everything! |
|
|
|
|
|
#3 (permalink) |
|
Diamond Member
![]() Join Date: Apr 2006
Location: Inside a pc
Posts: 19,730
|
To add a little protection from other things you disabled the Norton to give AVG 7.1 a free antivirus utility that often spots malwares. In addtiion to AdAware the freeware also by Grisoft is called Ewido. That catches what AdAware misses and vice versa.
AVG 7.1 Free edition is found at http://free.grisoft.com/doc/2/lng/us/tpl/v5 Ewido is found at http://free.grisoft.com/doc/ewido-an.../lng/us/tpl/v5 You may want to run a firewall along with these tools. The downloaders often leave a door open for adwares, spywares, trojan downloaders, and other types of malwares besides viruses. |
|
|
|
|
|
#4 (permalink) | ||
|
Silver Member
![]() Join Date: Oct 2005
Age: 22
Posts: 110
|
Quote:
Quote:
should i get AVG to replace Norton? which one would be better. Ewido is needed along with Spbot and Ad-Aware or as a replacement? |
||
|
|
|
|
|
#5 (permalink) |
|
Diamond Member
![]() Join Date: Apr 2006
Location: Inside a pc
Posts: 19,730
|
Ewido works works well along with AdAware. You can run those along with Spybot S+D. AVG would be an alternative to Norton 2006. This is why the advice to temporary disable Norton was given if you were going to try AVG out. Many have veeered away from Norton and ZZone Alarm alike in favor of AVG and firewalls like Kerrio and Sygate. Often with certain malwares you need to locate a special removal tool for one type.
|
|
|
|
|
|
#6 (permalink) | |
|
Administrator
![]() Join Date: Apr 2005
Location: London
Age: 26
Posts: 9,169
|
Quote:
__________________
What did one snow man say to the other? can you smell carrot? The fight is won or lost far away from witnesses - behind the lines, in the gym, and out there on the road, long before I dance under those lights. How you do anything, is how you do everything! |
|
|
|
|
|
|
#7 (permalink) |
|
Diamond Member
![]() Join Date: Apr 2006
Location: Inside a pc
Posts: 19,730
|
I wouldn't panic on something more then 5yrs. old at this point. The virus then was designed to hassle WIN 2.0, 3.0, .3.1, and the NT predecessor WIN 3.11 not 9X-ME, 2K, and XP as this late date. That wouldn't rule out another virus being sent around with a similar name however. AVG has a good email scanner builtin to detect these types of codes and updates itself when set to auto.
|
|
|
|
|
|
#8 (permalink) |
|
Platinum Member
![]() Join Date: Jul 2006
Posts: 812
|
If you are really worried, which I think you shouldn't because it is an old virus, do an online scan with Panda. http://www.pandasoftware.com/CMSPAND...CHEHINT=Guest#
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Format Windows XP HDD | tonymaclennan | Desktop Computers | 4 | 08-26-2006 05:22 PM |
| HDD Repartition & Format from WinXP... | Marzeth | Computer Memory and Hard Drives | 10 | 08-23-2006 08:26 PM |
| how can i format my external hdd so that it is 250gb | Jarbilong | Computer Memory and Hard Drives | 2 | 05-16-2006 04:15 PM |
| Can I rename computer without HDD Format? | helmie | Operating Systems | 3 | 01-07-2006 12:52 PM |
| Seagate HDD format | dlegault | Computer Memory and Hard Drives | 4 | 12-28-2004 02:31 PM |