OK 'tis nuclear time
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. [b]
O4 - HKCU..\Run: [drvsyskit] C:\WINDOWS\system32\drivers\hidr.exe
O23 - Service: W - Unknown owner - D:\TEMP\W.exe (file missing)
[/b]Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode.
-
Please download The Avenger by Swandog46 to your Desktop.
[*]Click on Avenger.zip to open the file[*]Extract avenger.exe to your desktop
-
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
[QUOTE]Drivers to unload:
drvsyskit
Files to delete:
C:\WINDOWS\system32\9B3821D7CB.sys
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\F5BC36F762.sys
[/quote]
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
- Now, start The Avenger program by clicking on its icon on your desktop.
[*] Under “Script file to execute” choose “Input Script Manually”.
[*]Now click on the Magnifying Glass icon which will open a new window titled “View/edit script”
[*] Paste the text copied to clipboard into this window by pressing (Ctrl+V).
[*] Click Done
[*] Now click on the Green Light to begin execution of the script
[*] Answer “Yes” twice when prompted.
- The Avenger will automatically do the following:
[*]It will Restart your computer. ( In cases where the code to execute contains “Drivers to Unload”, The Avenger will actually restart your system twice.)
[*]On reboot, it will briefly open a black command window on your desktop, this is normal.
[*]After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
[*] The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
- Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log by using Add/Reply
system
42
Hit a problem.
It rebooted twice, then after logging into windows I get the error:
Windows – No Disk
Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6f9c 75b6bf9c
And a cmd window saying:
The system cannot find the file specified.
Could Not Find C:\avenger*.reg
1 file(s) copied.
zip warning: C:/backup.zip not found or empty
adding: avenger/9B3821D7CB.sys (104 bytes security) (deflated 36%)
adding: avenger/avenger.txt (188 bytes security) (deflated 72%)
adding: avenger/backup.reg (188 bytes security) (stored 0%)
adding: avenger/F5BC36F762.sys (104 bytes security) (stored 0%)
I have left these windows open and run hjt, logs attached.
Ok you can close those windows and delete the following in Hijackthis,and the file on your drive. It appears that avenger stalled. However, there is no longer any sign of Bagle
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. [b]
O4 - HKLM..\Run: [esdaffjc] C:\ldttwerh.bat
[/b]Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
As a final check could you re-run DSS and let me now how your system is running now
system
44
Thanks again.
Ran HJT, but O4 - HKLM..\Run: [esdaffjc] C:\ldttwerh.bat wasn’t listed.
I connected the network cable, the status says connected, but no packets have been sent or received. I can’t connect to the internet or local computers on the same network, I can’t even ping the router.
I tried winsockxpfix but that didn’t help. I have checked all the usual IP settings and windows firewall is disabled. Any ideas?
DSS log attatched.
Well on the bright side DSS shows no problems. I see you have comodo firewall.
Have you allowed Ashwebserve access ?
Have you tried it with Avast paused
DavidR
46
Three avast functions that require access:
ashWebSv.exe - the avast Web Shield.
ashMaiSv.exe - the avast email scanner (for the Internet Mail provider).
avast.setup - this is what does the avast virus signature and program updates.
system
47

The virus had deleted my previous firewall (sygate) but must have left something behind. I uninstalled it, rebooted and packets started to flow.
FireFox still couldn’t find web sites, but I could ping their IP’s (DNS problem ??? ), so I tried IE, a window popped up asking me which file I wanted to crack ???, Avast icon disappeared and RKB is showing a whole list of files.
HJT log attatched.
Only one file that I can find no info on in your log nspksrv.exe.
Jotti File Submission:
[*]Please go to Jotti’s malware scan
[*]Copy and paste the following file path into the "File to upload & scan"box on the top of the page:
[*]C:\WINDOWS\system32\nspksrv.exe
[*] Click on the submit button
[*] Please post the results in your next reply.
.
Then
Please download Deckard’s System Scanner (DSS) and save it to your Desktop.
[*]Close all other windows before proceeding.
[*]Double-click on dss.exe and follow the prompts.
[*]When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.
system
49
DSS log attatched. Nothing found in NSPKSRV.EXE. It took a bit of finding, but its a network serial port driver, by Fabula Tech.
OK srosa has reared it’s head again but it is now deeply hidden
Please download F-Secure Blacklight (fsbl.exe) and save to your C:\ drive.
[*]Open a command window by going to Start > Run and typing: cmd
[*]Copy/paste or type the following in the command window: C:\fsbl.exe /expert
[*]Hit “Enter” to start the program and then close the cmd box.
[*]Accept the user agreement and click “Next”.
[*]Click “Scan”.
[*]After the scan is complete, click “Next”, then “Exit”.
[*]BlackLight will create a log in C:\ drive named “fsbl-xxxxxxx.log” (the xxxxxxx will be the date and time of the scan).
[*]The log will have a list of all items found. Do not choose to rename any yet!
I want to see the log first because legitimate items can also be present…like “wbemtest.exe” and "tcptest.exe.
[*]Exit Blacklight and post the contents of the log in your next reply.
Thanks for the info on that file
DavidR
51
@ essexboy
You need to edit your link to f-secure blacklight, as it is an ftp url you shouldn’t rap it in the URL tags as it puts an http:// in front of the ftp::// and that messes up the link.
e.g. ftp://ftp.f-secure.com/anti-virus/tools/fsbl.exe
system
52
Thanks again, but last night before I read you post I had a play around.
hidr.exe and srosa.sys came back, so I booted in safe mode and removed them. It appears one of the IE Add-ons is responsible for re-infecting. I disabled all add-ons in safe mode, now in normal mode IE works fine. Before IE would lockup if it didn’t have network access.
The DNS problem is caused by Comodo firewall. Even though I trust an application it is still blocking it, unless I select the ‘Skip advanced security checks’, in the miscellaneous tab in the application control rule.
I also un-installed avast and installed Comodos antivirus, because the infection kept deleting avast. However Comodo antivirus can’t enable the on access scanner. At that point I gave up and went to bed
I’ll give fsbl a go this evening and see what it comes up with.
I’m not with Comodo in this computer, but if I remember correctly, there is an entry for DNS queries in the advanced tab of settings of the firewall.
Don’t try to install two antivirus at the same time.
See http://forum.avast.com/index.php?topic=31559.msg263039#msg263039 to correct avast misinstallation problems…
Thankee David I actually amended the URL myself as it had changed from the original I had on my canned - Guess I blew it ??? However lesson learnt Ta
DavidR
55
Your welcome, it has caught me out a couple of times in the past.
system
56
Backlight didn’t find anything.
I thought I’d un-installed Avast before installing Comodo. Perhaps something was left behind. How do I completely remove Avast?
ASWclear from here will do that http://www.avast.com/eng/avast-uninstall-utility.html
Could you try an F-Secure online scan
Please run the F-Secure Online Scanner
Note: This Scanner is for Internet Explorer Only!
[*]Follow the Instruction Here for installation.
[*]Accept the License Agreement.
[*]Once the ActiveX installs,Click Full System Scan
[*]Once the download completes,the scan will begin automatically.
[*]The scan will take some time to finish,so please be patient.
[*]When the scan completes, click the Automatic cleaning (recommended) button.
[*]Click the Show Report button and Copy&Paste the entire report in your next reply.