I was glad to find this site after I accidently aquired the Storm Trojan. I thought I got it all and 2 days later, things slowed again. So I found your Cleaning guide and ran the crap out of everything. Some more stuff was found, and now all the scanners you suggest find the system 'clean'.
However, I also ran the IseeyouXP.bat because I feel my performance is a little slow still, and i'm afraid that i will have to blow another entire day deleting and scanning if a piece of the Storm Trojan is left to copy itself.
I am attaching the results of IseeyouXP.bat as a txt file. I am not attaching the logs from the anti-virus scans, because they all come clean now. The date of the infection was most likely July 5th at about 130 pm.
Thank you in advace for your help! I am trying to write a thesis here! what a crappy couple of days!
ISeeYouXP v1.3.0-v2.0 Beta 12 Copyright - ShadowPuterDude ISeeYouXP v1.2.9 and earlier Copyright - PhilliePhan ------------------------------------------------------------------------------------ **** PLEASE NOTE THAT MOST (if not ALL) OF THE ITEMS BELOW ARE NOT BADDIES! **** **** PLEASE CONSULT A KNOWLEDGEABLE PERSON BEFORE TAKING ANY ACTION. **** ************************************************************************************
Windows OS is:
Microsoft Windows XP [Version 5.1.2600] It's Mon July 9, 2007 08:50:53 PM
ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Chemist by Day\Application Data CLIENTNAME=Console CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=LINDSAY-LAPTOP ComSpec=C:\windows\system32\cmd.exe errcode=0 FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Chemist by Day LOGONSERVER=\\LINDSAY-LAPTOP NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\windows\system32;C:\windows;C:\windows\system32\wbem;C:\Program Files\MATLAB\R2006b\bin;C:\Program Files\MATLAB\R2006b\bin\win32; PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 6, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0d06 ProgramFiles=C:\Program Files PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\windows TEMP=C:\DOCUME~1\CHEMIS~1\LOCALS~1\Temp TMP=C:\DOCUME~1\CHEMIS~1\LOCALS~1\Temp USERDOMAIN=LINDSAY-LAPTOP USERNAME=Chemist by Day USERPROFILE=C:\Documents and Settings\Chemist by Day windir=C:\windows
Microsoft Windows Malicious Software Removal Tool v1.30, June 2007 Started On Mon Jul 09 12:31:56 2007
Extended Scan Results ---------------- ->Scan ERROR: resource file://C:\pagefile.sys (code 0x00000020 (32)) ->Scan ERROR: resource file://C:\System Volume Information\_restore{BDBBC479-CA85-4D56-9939-F29E82DD6B3C}\RP232\A0023049.msi->(MSI Stream 42) (code 0x0000000B (11)) ->Scan ERROR: resource file://C:\WINDOWS\Installer\d8eaaf.msi->(MSI Stream 73) (code 0x0000000B (11)) No infection found as part of the extended scan
Results Summary: ---------------- No infection found.
Return code: 0 Microsoft Windows Malicious Software Removal Tool Finished On Mon Jul 09 15:13:15 2007
---------------------------------------------------------------------------- Listing HKCU Explorer\Advanced//Hidden and SuperHidden Registry Keys if Hidden = 0 then Hidden Files and Folders are not shown if SuperHidden = 1 is the desired default value. if ShowSuperHidden = 0 then System Files are not shown if HideFileExt = 1 then File Extension are not shown We want their values to be (from top to bottom) 1,1,1,0 ----------------------------------------------------------------------------
Examining Select Windows Registry Keys ------------------------------------------------------------------------------------
-------------------------------------------------------------------------- Items Found in ZoneMap\Domains: --------------------------------------------------------------------------
---------------------------------------------------------------------------- Current User ZoneMap ProtocolDefaults ----------------------------------------------------------------------------
-------------------------------------------------------------------------- Items in the Root Directory: --------------------------------------------------------------------------
Locating all files created in C:\
"C:\" 801AAC~1 Dec 26 2006 "801aacb8c3be531c00" ACDFREE8 Jan 23 2007 "ACDFREE8" autoexec.bat Dec 25 2006 0 "AUTOEXEC.BAT" boot.ini Dec 25 2006 46 "boot.ini" CONFIG.MSI May 17 2007 "Config.Msi" config.sys Dec 25 2006 0 "CONFIG.SYS" CYGWIN Mar 28 2007 "cygwin" DELL Dec 25 2006 "dell" DOCUME~1 Dec 25 2006 "Documents and Settings" DOWNLO~1 Jun 26 2007 "downloadedTemplate" helpas~1.htm Jun 26 2007 6473 "helpasapcontact.htm" helpas~2.htm Jun 26 2007 83 "helpasapabout.htm" io.sys Dec 25 2006 0 "IO.SYS" ISEEYO~1 Jul 9 2007 "ISeeYouXP" MININT Dec 25 2006 "minint" msdos.sys Dec 25 2006 0 "MSDOS.SYS" MSOCACHE Dec 25 2006 "MSOCache" ntdetect.com Dec 26 2006 47564 "NTDETECT.COM" ntldr Dec 26 2006 250032 "ntldr" pagefile.sys Jul 9 2007 780140544 "pagefile.sys" peboot.bin Dec 25 2006 8192 "peboot.bin" peldr Aug 28 2002 245920 "peldr" PROGRA~1 Dec 25 2006 "Program Files" RECYCLER Dec 27 2006 "RECYCLER" SFSCHLR Dec 26 2006 "SFSCHLR" SFSCHO~1 Dec 26 2006 "SFScholarToolbar" SYSTEM~1 Dec 25 2006 "System Volume Information" WINDOWS Dec 25 2006 "WINDOWS"
28 items found: 12 files (6 H/S), 16 directories (4 H/S). Total of file sizes: 780,698,854 bytes 744.53 M
-------------------------------------------------------------------------- Locating all Backup files on C: --------------------------------------------------------------------------
Locating all *.BAK* files
"C:\WINDOWS\" imsins.bak Jun 14 2007 1374 "imsins.BAK"
"C:\WINDOWS\inf\" mplayer2.bak Jan 8 2004 18755 "mplayer2.bak"
"C:\Documents and Settings\Chemist by Day\Application Data\Microsoft\Internet Explorer\" brndlog.bak Dec 25 2006 141 "brndlog.bak"
"C:\Documents and Settings\Default User\Application Data\Microsoft\Internet Explorer\" brndlog.bak Dec 25 2006 113 "brndlog.bak"
"C:\Documents and Settings\Lindsay\Application Data\Microsoft\Internet Explorer\" brndlog.bak Dec 25 2006 141 "brndlog.bak"
"C:\WINDOWS\PCHealth\HelpCtr\Config\Cache\" profes~1.bak Dec 26 2006 170684 "Professional_32_1033.dat.bak"
"C:\Documents and Settings\All Users\Application Data\Microsoft\OFFICE\DATA\" opa11.bak Oct 17 2002 8200 "OPA11.BAK"
"C:\Documents and Settings\Lindsay\Application Data\Intel\Wireless\WLANProfiles\" profil~1.bak Jan 15 2007 11904 "Profiles.enc.bak"
"C:\Documents and Settings\Administrator.LINDSAY-LAPTOP\Application Data\Mozilla\Firefox\Profiles\vb3x18jq.default\" bookma~1.bak Jul 9 2007 7191 "bookmarks.bak"
"C:\Documents and Settings\Chemist by Day\Application Data\Mozilla\Firefox\Profiles\kezqkn8x.default\" bookma~1.bak Jul 9 2007 17395 "bookmarks.bak" bookma~2.bak Jun 13 2007 17395 "bookmarks.html.sbsd.bak"
"C:\Documents and Settings\Lindsay\Application Data\Mozilla\Firefox\Profiles\vi2rarfs.default\" bookma~1.bak Jun 29 2007 7191 "bookmarks.bak"
"C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\" brndlog.bak Dec 25 2006 113 "brndlog.bak"
"C:\Program Files\MATLAB\R2006b\toolbox\rtw\targets\tasking\tasking\default_project_options\c166\ede\" apd9fc~1.bak Aug 4 2006 3488 "app_c167cs_sim.bak" app_c1~1.bak Aug 4 2006 3277 "app_c166_sim.bak" app_c1~2.bak Aug 4 2006 3478 "app_c167cr_hw.bak" app_c1~3.bak Aug 4 2006 3381 "app_c167cr_sim.bak" app_c1~4.bak Aug 4 2006 3637 "app_c167cs_hw.bak" app_st~1.bak Aug 4 2006 3598 "app_st10f269_hw.bak" app_st~2.bak Aug 4 2006 3449 "app_st10f269_sim.bak" app_xc~1.bak Aug 4 2006 3650 "app_xc167ci_hw.bak" app_xc~2.bak Aug 4 2006 3556 "app_xc167ci_sim.bak" lib_c1~1.bak Aug 4 2006 7383 "lib_c166_sim.bak" lib_c1~2.bak Aug 4 2006 7414 "lib_c167cr_hw.bak" lib_c1~3.bak Aug 4 2006 7426 "lib_c167cr_sim.bak" lib_c1~4.bak Aug 4 2006 7414 "lib_c167cs_hw.bak" lib_st~1.bak Aug 4 2006 7436 "lib_st10f269_hw.bak" lib_st~2.bak Aug 4 2006 7448 "lib_st10f269_sim.bak" lib_xc~1.bak Aug 4 2006 7427 "lib_xc167ci_hw.bak" lib_xc~2.bak Aug 4 2006 7439 "lib_xc167ci_sim.bak" lic8ab~1.bak Aug 4 2006 7426 "lib_c167cs_sim.bak"
"C:\Program Files\MATLAB\R2006b\toolbox\rtw\targets\tasking\tasking\default_project_options\c563\ede\" app_ds~1.bak Aug 4 2006 3295 "app_dsp563xx_sim.bak" app_ds~2.bak Aug 4 2006 3345 "app_dsp566xx_sim.bak" lib_ds~1.bak Aug 4 2006 6121 "lib_dsp563xx_sim.bak" lib_ds~2.bak Aug 4 2006 6171 "lib_dsp566xx_sim.bak"
"C:\Program Files\MATLAB\R2006b\toolbox\rtw\targets\tasking\tasking\default_project_options\carm\ede\" app_ar~1.bak Aug 4 2006 3194 "app_arm_sim.bak" app_ar~2.bak Aug 4 2006 3229 "app_arm_sim_big_endian.bak" lib_ar~1.bak Aug 4 2006 4917 "lib_arm_sim.bak" lib_ar~2.bak Aug 4 2006 5007 "lib_arm_sim_big_endian.bak"
"C:\Program Files\MATLAB\R2006b\toolbox\rtw\targets\tasking\tasking\default_project_options\cc51\ede\" app_i8~1.bak Aug 4 2006 3315 "app_i8051_sim.bak" lib_i8~1.bak Aug 4 2006 4689 "lib_i8051_sim.bak"
"C:\Program Files\MATLAB\R2006b\toolbox\rtw\targets\tasking\tasking\default_project_options\cm16c\ede\" app_m1~1.bak Aug 4 2006 3278 "app_m16c_sim.bak" app_r8~1.bak Aug 4 2006 3343 "app_r8ctiny_sim.bak" lib_m1~1.bak Aug 4 2006 5678 "lib_m16c_sim.bak" lib_r8~1.bak Aug 4 2006 5761 "lib_r8ctiny_sim.bak"
"C:\Program Files\MATLAB\R2006b\toolbox\rtw\targets\tasking\tasking\default_project_options\ctc\ede\" app_tr~1.bak Aug 4 2006 3950 "app_tricore_1766b.bak" app_tr~2.bak Aug 4 2006 4019 "app_tricore_1796b.bak" app_tr~3.bak Aug 4 2006 3327 "app_tricore_sim.bak" app_tr~4.bak Aug 4 2006 3563 "app_tricore_sim_misra.bak" lib_tr~1.bak Aug 4 2006 7101 "lib_tricore_1766b.bak" lib_tr~2.bak Aug 4 2006 7170 "lib_tricore_1796b.bak" lib_tr~3.bak Aug 4 2006 6460 "lib_tricore_sim.bak" lib_tr~4.bak Aug 4 2006 6514 "lib_tricore_sim_misra.bak"
59 items found: 59 files, 0 directories. Total of file sizes: 954,881 bytes 932.50 K
-------------------------------------------------------------------------- Locating all copies of Internet Explorer on C: --------------------------------------------------------------------------
Locating all copies of Internet Explorer
"C:\Program Files\Internet Explorer\" iexplore.exe Aug 4 2004 93184 "iexplore.exe"
"C:\WINDOWS\$NtServicePackUninstall$\" iexplore.exe Aug 28 2002 91136 "iexplore.exe"
"C:\WINDOWS\ServicePackFiles\i386\" iexplore.exe Aug 4 2004 93184 "iexplore.exe"
3 items found: 3 files, 0 directories. Total of file sizes: 277,504 bytes 271.00 K
-------------------------------------------------------------------------- Locating all copies of Windows Explorer on C: --------------------------------------------------------------------------
Locating all copies of Windows Explorer
"C:\WINDOWS\" explorer.exe Aug 4 2004 1032192 "explorer.exe"
"C:\WINDOWS\$NtServicePackUninstall$\" explorer.exe Aug 28 2002 1004032 "explorer.exe"
"C:\WINDOWS\ServicePackFiles\i386\" explorer.exe Aug 4 2004 1032192 "explorer.exe"
3 items found: 3 files, 0 directories. Total of file sizes: 3,068,416 bytes 2.93 M
-------------------------------------------------------------------------- Items in Document and Settings: --------------------------------------------------------------------------
Listing contents of C:\Documents and Settings
"C:\Documents and Settings\" ADMINI~1 Jul 9 2007 "Administrator" ADMINI~1.LIN Jul 9 2007 "Administrator.LINDSAY-LAPTOP" ALLUSE~1 Dec 25 2006 "All Users" CHEMIS~1 Dec 25 2006 "Chemist by Day" DEFAUL~1 Dec 25 2006 "Default User" LINDSAY Dec 25 2006 "Lindsay" LOCALS~1 Dec 25 2006 "LocalService" NETWOR~1 Dec 25 2006 "NetworkService"
1 item found: 1 file, 0 directories. Total of file sizes: 849 bytes 0.83 K
-------------------------------------------------------------------------- Start Menu Items: --------------------------------------------------------------------------
Locating all files created inC:\Documents and Settings\Chemist by Day\Start Menu within the last 90 days.
No matches found.
Locating all files created in C:\Documents and Settings\Chemist by Day\Start Menu\Programs\Startup within the last 90 days.
No matches found.
Locating all files created in C:\Documents and Settings\All Users\Start Menu within the last 90 days.
No matches found.
Locating all files created in C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ within the last 90 days.
1 item found: 1 file, 0 directories. Total of file sizes: 2,447 bytes 2.39 K
-------------------------------------------------------------------------- Application Data Items: --------------------------------------------------------------------------
Locating all files created in C:\Documents and Settings\Chemist by Day\Application Data\ within the last 90 days.
"C:\Documents and Settings\Chemist by Day\Application Data\" GOOGLE May 11 2007 "Google" GRISOFT Jul 9 2007 "Grisoft" NVU Jun 26 2007 "Nvu"
3 items found: 0 files, 3 directories.
Locating all files created in C:\Documents and Settings\Chemist by Day\Local Settings\Application Data\ within the last 90 days.
"C:\Documents and Settings\Chemist by Day\Local Settings\Application Data\" dcbc2a~1.ini May 2 2007 28160 "DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini" GOOGLE May 11 2007 "Google"
2 items found: 1 file, 1 directory. Total of file sizes: 28,160 bytes 27.50 K
Locating all files created in C:\Documents and Settings\All Users\Application Data\ within the last 90 days.
-------------------------------------------------------------------------- C:\Documents and Settings\Chemist by Day\Local Settings\TEMP: --------------------------------------------------------------------------
Locating all files created in C:\Documents and Settings\Chemist by Day\Local Settings\TEMP within the last 90 days.
-------------------------------------------------------------------------- Items in Templates Folder: --------------------------------------------------------------------------
Locating all files created in C:\Documents and Settings\Chemist by Day\Templates
"C:\Documents and Settings\Chemist by Day\Templates\" amipro.sam Jan 8 2004 4570 "amipro.sam" excel.xls Jan 8 2004 5632 "excel.xls" excel4.xls Jan 8 2004 1518 "excel4.xls" lotus.wk4 Jan 8 2004 2448 "lotus.wk4" powerpnt.ppt Jan 8 2004 12288 "powerpnt.ppt" presenta.shw Jan 8 2004 461 "presenta.shw" quattro.wb2 Jan 8 2004 4017 "quattro.wb2" sndrec.wav Jan 8 2004 58 "sndrec.wav" winword.doc Jan 8 2004 4608 "winword.doc" winword2.doc Jan 8 2004 1769 "winword2.doc" wordpfct.wpd Jan 8 2004 30 "wordpfct.wpd" wordpfct.wpg Jan 8 2004 57 "wordpfct.wpg"
12 items found: 12 files, 0 directories. Total of file sizes: 37,456 bytes 36.58 K
-------------------------------------------------------------------------- Items in Program Files: --------------------------------------------------------------------------
Locating all files created in C:\Program Files\ within the last 90 days.
"C:\Program Files\" APACHE~1 May 17 2007 "Apache Group" GOOGLE May 11 2007 "Google" GRISOFT Jul 9 2007 "Grisoft" HJT Jul 9 2007 "HJT" MYSQL May 17 2007 "MySQL" NVU Jun 26 2007 "Nvu" PHP May 17 2007 "PHP" QUICKT~2 May 28 2007 "Quick Terrain Reader"
8 items found: 0 files, 8 directories.
Locating all files created in C:\Program Files\Common Files\ within the last 90 days.
No matches found.
Locating all files created in C:\Program Files\Common Files\Microsoft Shared\Web Folders within the last 90 days.
No matches found.
-------------------------------------------------------------------------- Items in the Windows Directory: --------------------------------------------------------------------------
Locating all files created in C:\windows\ within the last 90 days.
"C:\WINDOWS\" $N20DA~1 Apr 13 2007 "$NtUninstallKB931261$" $N30DA~2 Jun 14 2007 "$NtUninstallKB935840$" $N30DC~1 Jun 14 2007 "$NtUninstallKB929123$" $N4009~1 May 23 2007 "$NtUninstallKB927891$" $N50EE~1 Apr 13 2007 "$NtUninstallKB931784$" $N64D6~1 Apr 13 2007 "$NtUninstallKB932168$" $N64D6~2 Apr 13 2007 "$NtUninstallKB930178$" $N68D6~1 Jun 14 2007 "$NtUninstallKB933566$" $N70DE~1 May 9 2007 "$NtUninstallKB931768$" $N74A6~1 May 9 2007 "$NtUninstallKB930916$" $N88C2~1 Jun 14 2007 "$NtUninstallKB935839$" 0.log Jul 9 2007 0 "0.log" comsetup.log Jun 14 2007 229237 "comsetup.log" CSC Jul 9 2007 "CSC" faxsetup.log Jun 14 2007 937624 "FaxSetup.log" iis6.log Jun 14 2007 1088716 "iis6.log" imsins.bak Jun 14 2007 1374 "imsins.BAK" imsins.log Jun 14 2007 1374 "imsins.log" kb927891.log May 23 2007 7599 "KB927891.log" kb929123.log Jun 14 2007 12538 "KB929123.log" kb930178.log Apr 13 2007 12513 "KB930178.log" kb930916.log May 9 2007 10432 "KB930916.log" kb931261.log Apr 13 2007 12208 "KB931261.log" kb931768.log May 9 2007 12654 "KB931768.log" kb931784.log Apr 13 2007 14033 "KB931784.log" kb932168.log Apr 13 2007 12305 "KB932168.log" kb933566.log Jun 14 2007 18967 "KB933566.log" kb935839.log Jun 14 2007 10994 "KB935839.log" kb935840.log Jun 14 2007 10987 "KB935840.log" matlab.ini May 1 2007 157 "matlab.ini" medctroc.log Jun 14 2007 65594 "MedCtrOC.log" MINIDUMP Jul 6 2007 "Minidump" msgsocm.log Jun 14 2007 47149 "msgsocm.log" msmqinst.log Jun 14 2007 302482 "msmqinst.log" netfxocm.log Jun 14 2007 165235 "netfxocm.log" ntbtlog.txt Jul 9 2007 379976 "ntbtlog.txt" ntdtcs~1.log Jun 14 2007 138389 "ntdtcsetup.log" ocgen.log Jun 14 2007 471724 "ocgen.log" ocmsn.log Jun 14 2007 28904 "ocmsn.log" qtfont.for May 5 2007 1409 "QTFont.for" qtfont.qfn Jul 6 2007 54156 "QTFont.qfn" QUICKT~1 May 28 2007 "Quick Terrain Reader" schedlgu.txt Jul 9 2007 2226 "SchedLgU.Txt" setupapi.log Jul 9 2007 838058 "setupapi.log" tabletoc.log Jun 14 2007 48121 "tabletoc.log" thumbs.db Jun 12 2007 7168 "Thumbs.db" tsoc.log Jun 14 2007 436071 "tsoc.log" updspapi.log Jun 14 2007 83563 "updspapi.log" vpc32.ini Jul 9 2007 0 "VPC32.INI" wiadebug.log Jun 22 2007 411 "wiadebug.log" wiaservc.log Jun 22 2007 49 "wiaservc.log" win.ini Jul 9 2007 642 "win.ini" window~2.log Jul 9 2007 60240 "WindowsUpdate.log" wmsetup.log Jul 5 2007 28755 "wmsetup.log"
54 items found: 40 files (2 H/S), 14 directories (11 H/S). Total of file sizes: 5,554,034 bytes 5.29 M
-------------------------------------------------------------------------- C:\windows\Downloaded Program Files: --------------------------------------------------------------------------
Locating all files created in C:\windows\Downloaded Program Files\ within the last 90 days.
Locating all files created in C:\windows\system32\com within the last 90 days.
No matches found.
-------------------------------------------------------------------------- C:\windows\system32\components: -------------------------------------------------------------------------- Locating all files created in C:\windows\system32\components within the last 90 days.
The problem with File Attachments has been corrected.
The installed version of Java on this compter is out-dated. Install Java Runtime Environment (JRE) 6u2 available from Major Geeks. Uninstall all older versions of Java on your computer, before installing the latest version of Java.
Choose Tools -> Delete Temp Files and click Delete Selected Temp Files Then after it deletes the files click the Exit (Save Settings) button.
NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
Return to Killbox, go to the File menu, and choose Paste from Clipboard.
Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.
Now boot into SAFE MODE
Open ExplorerXP navigate to and DELETE the following: