system
January 22, 2010, 4:05am
1
Hello all,
Earlier today, avast, in addition to malewarebytes, picked up a few viruses on my machine and removed them.
Now, I’ve started to notice firefox, in addition to opera, are redirecting me to random sites when I try searching for things on google. If I click on search results, I am redirected to sites like “http://freecaselaw.com/search.php ” or “http://guitarclassifieds.com/search.php ” or “http://palmgamepad.com/search.php ”, all usually ending with search.php.
I looked at my startup entries via msconfig and found multiple entries of “sysdiagol.exe” located C:/windows/sysdiagol.exe in addition to registry entries. However, I checked in my windows folder and was not able to find it. I did a scan of my Windows folder with Avast(up to date definitions), and it found nothing.
This must be brand new as well, because a google search of “sysdiagol” brings up only 2 results. I discovered the program Prevx, which finds the file, but won’t remove it unless I pay. It also tells me it’s located in C:/windows/sysdiagol.exe.
They have information on their webpage regarding this virus, which can be found here: http://www.prevx.com/filenames/463796697114165589-X1/SYSDIAGOL.EXE.html
I’ve just scanned with Spybot, and it doesn’t find anything besides a windows firewall override, which I’m assuming sysdiagol did.
Does anyone have any ideas or suggestions in regards to removing this?
Are you able to disable sysdiagol.exe via msconfig?
Please post a HijackThis! log .
These two free scanners are also worth a try:
SUPERAntiSpyware Free
a-Squared Free
system
January 23, 2010, 2:33am
3
I have it unchecked as a startup program, but that isnt doing anything because it continuous to function. I’ve scanned with SUPERantispyware which only found some tracking cookies. I also tried scanning with spybot as well as malwarebytes, and neither found anything. This “sysdiagol.exe” is so well hidden, nothing is picking it up. It’s considered “cloaked malware” by that prevx site, so I’m assuming it’s some type of rootkit.
I scanned with hijackthis, here is the log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:18:59 PM, on 1/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Creative\Shared Files\CTAudSvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
F:\Tools\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM..\Run: [Windows Defender] “C:\Program Files\Windows Defender\MSASCui.exe” -hide
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU..\Run: [H/PC Connection Agent] “C:\Program Files\Microsoft ActiveSync\wcescomm.exe”
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\Shockwave 11\SwHelper_1150600.exe -Update -1150600 -“Mozilla/5.0_(Windows;_U;_Windows_NT_5.1;_en-US;_rv:1.9.1.3)Gecko/20090824_Firefox/3.5.3 (.NET_CLR_3.5.30729)” -“http://www.regentsprep.org/Regents/physics/phys01/friction/default.htm ”
O4 - Startup: Stardock ObjectDock.lnk = D:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra ‘Tools’ menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Program Files\AIM\aim.exe
O9 - Extra button: Encarta Search Bar - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra ‘Tools’ menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra ‘Tools’ menuitem: @xpsp3res.dll ,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ‘Tools’ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1199398582203
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su2/ocx/15106/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip..{14EC0323-D474-4052-ADF6-59499FB9E124}: NameServer = 68.87.64.146,68.87.75.194
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: astcc - Unknown owner - C:\WINDOWS\system32\AstSrv.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Startup and Shutdown Monitor service (PCToolsSSDMonitorSvc) - PC Tools - C:\Program Files\Common Files\PC Tools\sMonitor\StartManSvc.exe
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: UG - Unknown owner - T:\User\TMP\UG.exe (file missing)
–
End of file - 8498 bytes
Anything stick out in the log?
The only solution I can think of right now is reformatting, which I really don’t have time to do. Do you think I have any alternatives?
This seems to be a backdoor (identification again by PrevX):
O23 - Service: UG - Unknown owner - T:\User\TMP\UG.exe (file missing)
I agree it’s probably a rootkit: the best way to deal with hidden malware is from outside the operating system.
You could boot from a Linux Live CD, eg Ubuntu, and search for and delete the files from Linux- they will not be active and cannot hide themselves.
https://help.ubuntu.com/community/LiveCD
Alternatively, run a rescue CD (many of these are also Linux plus a virus scanner).
avast! doesn’t do one, but there are several to choose from.
Rescue CD’s. Download and burn the ISO disk image on an uninfected computer. Boot the infected computer from the disk and run a virus scan (after updating virus definitions if this option is present).
Programs like Nero and Roxio can burn ISO images- you may have one of these on your computer. If not, there are free programs that will do it:
http://pcsupport.about.com/od/toolsofthetrade/ht/burnisofile.htm
Dr.Web LiveCD
Kaspersky Rescue Disk
AntiVir Rescue CD
Bitdefender Rescue CD
F-Secure Rescue CD
system
January 23, 2010, 8:22am
5
Thanks a lot for the resources. I’m trying my luck with the bitdefender rescue disk. I was able to locate the “sysdiagol.exe” file in my windows folder, however when I scan it with bitdefender it tells me it doesn’t detect anything. Should I manually delete the file? I believe it has created multiples of itself in different locations and if the scanner is not picking them up there is no way for me to tell if I’ve found everything.
It’s certainly not a system file and the evidence seems overwhelming that it’s malware. If you want to play it extra safe, you could rename it.
I don’t know if BitDefender has a search facility.
Have a look round and rename any examples you find.
Do the same for T:\User\TMP\UG.exe
Reboot and see if you still get the redirects.
Also, when you reboot, could you submit the renamed sysdiagol.exe to VirusTotal ?
That way, all AV’s will be able to add detection.
system
January 25, 2010, 6:27am
7
Well, I removed the files but the problem persists, however, I was able to locate a few additional trojans on my drive using avast today. I then tried a malwarebytes scan and avast picked something up through that scan, it found a download ft trojan. I tried quarantining it but avast was unable because it was being used by another process. What is interesting is the file path is “C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\M3WD4490\go[1].php”. When I get redirected in my browser, the sites are xxxxxx.php. I went to look for the file in the Local Settings folder, but there was no Temporary Internet Files folder, not even a hidden one. So I used knoppix and went in and deleted the entire Content.IE5 folder hoping to completely remove the file, however the problem still persists!!!
My thoughts are whatever is in my system has dug itself deep into my registry and nothing is finding it. I’m not really sure what other options I have besides reformatting.
Were you able to send a sample to VirusTotal?
There is obviously something we’re missing.
You could try a scan with Clam in Knoppix:
http://syntheticlibrarian.com/2005/09/22/using-knoppix-and-clam-anti-virus-to-scan-infected-pcs
I suspect it’s possible to install avast! in Knoppix too, but I can’t find my copy of Knoppix to check that.
Update MalwareBytes, avast!, SusperAntiSpyware and scan again- also try a-Squared mentioned below because it has a very good detection rate.
If non of that works, post an OTL log:
http://forum.avast.com/index.php?topic=53253.0
system
January 28, 2010, 5:14pm
9
good day everyone.I have a friend who proposed me to download AVG Free 9.0.
so i did.at first nothing happened,but after a little while the AVG found the trojan and i hope that now itall over.i said i hope because i
m not the best man existing about pcs.so if anyone try my advise ,i am looking forward in helping me fyrther!
good day everyone.I have a friend who proposed me to download AVG Free 9.0.
so i did.at first nothing happened,but after a little while the AVG found the trojan and i hope that now itall over.i said i hope because i
m not the best man existing about pcs.so if anyone try my advise ,i am looking forward in helping me fyrther!
Please start your own topic, where I’m sure someone will help (even though this is the avast! forum, not AVG’s. )
system
February 15, 2010, 7:25pm
11
I was able to get rid of the virus in case some one want to know…
It took some time to figure it out.
Let me know if you want to know how I did it.
Regards!